Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Red Hat OpenStack Platform 10: Important Security Update for qemu-kvm-rhev

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: qemu-kvm-rhev security update Advisory ID: RHSA-2020:4176-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:4176 Issue date: 2020-10-05 CVE Names: CVE-2020-14364 ==================================================================== 1. Summary: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 10.0 - x86_64 3. Description: KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products. Security Fix(es): * usb: out-of-bounds r/w access issue while processing usb packets (CVE-2020-14364) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1869201 - CVE-2020-14364 QEMU: usb: out-of-bounds r/w access issue whileprocessing usb packets 6. Package List: Red Hat OpenStack Platform 10.0: Source: qemu-kvm-rhev-2.12.0-33.el7_7.12.src.rpm x86_64: qemu-img-rhev-2.12.0-33.el7_7.12.x86_64.rpm qemu-kvm-common-rhev-2.12.0-33.el7_7.12.x86_64.rpm qemu-kvm-rhev-2.12.0-33.el7_7.12.x86_64.rpm qemu-kvm-rhev-debuginfo-2.12.0-33.el7_7.12.x86_64.rpm qemu-kvm-tools-rhev-2.12.0-33.el7_7.12.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-14364 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX3uF3tzjgjWX9erEAQizvxAAmS4bb6OAiD6o1/jDymcGuVra8q80zIuJ 26Egxf0mtoz5ztjdk9mLhJvns/1IgmPexZE1OegPsvHk1EAaZp1FEBRG41ltiikh KoOTzrCcb+cWsnMVKmSG55s4tyi006tEk40xWQR69++kVGUCns/aCQaJR5GQQkWQ K6lqh/05EYKw4rKZev1Diu8d5iVXpQ96EdRZrl41AFWGOr9TtFv+N0b9QeJJ4IFh CoXDDjhJHBDOXRh4MAZnXiQUQN4KfpJhocer5uELT8/p52+sJwQGsis1QjBYJzM1 ZEADJh9VD8rIMSXgTCAh6+jsH1fEm0bFV403Yzv2aWr9m9VxZkiMd1bX7W9UV4vw c/hrtHoqoGeidRz/nwTeGSmsVenpwlAmi/A0BS2CyVKEl/p5KKkMIlH2/sGo498e 61ua3OEzqJhMn14SShxsVKNyf2DCGfh0R8dmVqqq0J74Z4PqsyEDuyQzCfz6OjZW GxfoSBImpwEPf6+7Oj2tp2nDjwtqgKNHLIr4TkqVZsEU75ZyhOQSTz4memfd1+gC ny2OPPQw34qqFe+aLuyCEhpQsueMZ1SNuxIAn0X/Vjr+pdHAHxrbHLm0kXRY3u+b pU88UYRMvu19FDnPeYy9hii8BrwbtfSwGQoZee40Ez6NzaY6q9qioFTGgpC99wtz L/K/dHsOl4s=B5HA -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Canonical releases significant libvirt security patch for Ubuntu Cloud Infrastructure correcting major privilege vulnerabilities.. Red Hat OpenStack, qemu-kvm security, out-of-bounds access, important update, software security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 05, 2020 Important Red Hat
98

Red Hat Enterprise Linux 7.6: RHSA-2020-4052-01 Critical USB Access Flaw

An update for qemu-kvm is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: qemu-kvm security update Advisory ID: RHSA-2020:4052-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4052 Issue date: 2020-09-29 CVE Names: CVE-2020-14364 ==================================================================== 1. Summary: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.6) - x86_64 3. Description: Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM. Security Fix(es): * QEMU: usb: out-of-bounds r/w access issue while processing usb packets (CVE-2020-14364) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, shut down all running virtualmachines. Once all virtual machines have shut down, start them again for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1869201 - CVE-2020-14364 QEMU: usb: out-of-bounds r/w access issue while processing usb packets 6. Package List: Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.6): Source: qemu-kvm-1.5.3-160.el7_6.8.src.rpm x86_64: qemu-img-1.5.3-160.el7_6.8.x86_64.rpm qemu-kvm-1.5.3-160.el7_6.8.x86_64.rpm qemu-kvm-common-1.5.3-160.el7_6.8.x86_64.rpm qemu-kvm-debuginfo-1.5.3-160.el7_6.8.x86_64.rpm qemu-kvm-tools-1.5.3-160.el7_6.8.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.6): Source: qemu-kvm-1.5.3-160.el7_6.8.src.rpm x86_64: qemu-img-1.5.3-160.el7_6.8.x86_64.rpm qemu-kvm-1.5.3-160.el7_6.8.x86_64.rpm qemu-kvm-common-1.5.3-160.el7_6.8.x86_64.rpm qemu-kvm-debuginfo-1.5.3-160.el7_6.8.x86_64.rpm qemu-kvm-tools-1.5.3-160.el7_6.8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-14364 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX3NRZtzjgjWX9erEAQjmIg//UH7HeBSkE96gdYB8FEAJONFvw2PonCjH oxk4qJVUI+XA6IgxFVqFC7pPaTUGtUyHMdOVQBCkb0SuPw6DFAT84VAcX8vfykPW CTC2bo/VIvdQqwpNrJQQL4ZN49WI6HhrTJP+bzMleg32Dp1myqBi32dBtJBKAwwH k3x9Z4qU4L1IQQ2GURY+wu2sEyA93T9qhtGETvO/TQZ1I9iz5JfEca1edxs58EHx BIWJXtAL5C2/QdS5tC/XY7HpUdlOGuCgtwqFNwkgtOIwEwX1SpFTAqzu9d4bqo0M kdpnfRGu+OvTJ3AJjUjx8HiRZNYgNVp98ZkucYj/WLzTdP2rnkbBIu4Vv1AbID9U mIIaAwZsTh/CFdVekbMr/xBHgJtTQ/S9FZYP2K34VG1xBCtmFGxgJO5wScKhoLdx tk2mrAH86b6Ncs2Is2uvkZbs9nXALmvX0aK2zzC4r7922MugePfcGHlIifY+92uf Bpd2Nn9mLAIZyMDKd3xJN0SGTG55NHH2d0TXbz/Yu0SEu9Ie4D76mvaahGPA0fo4 6zImpdOiQSZgkb9DINfmxakUjcvRWre+6gNPZJS/YuirShyA89Ei7mOGfHirCiiB pb64+OdEfj0J64tN15eIJMY8paebu4Mrdf3BfKgRxnGiFV/8YnP0h1kyxvSbyjix xr5nNmktosI=dTBV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Stay updated on the critical qemu-kvm security patch for Red Hat, addressing vulnerabilities that threaten system integrity and requiring prompt action. Red Hat Update, qemu-kvm Security, Linux EUS Advisory, Important Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 29, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200