Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia 9: 2024-0233 High: Chromium Browser Security Fixes and Updates

High CVE-2024-6100: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n) participating in SSD Secure Disclosure's TyphoonPWN 2024 on 2024-06-04 High CVE-2024-6101: Inappropriate implementation in WebAssembly. Reported by @ginggilBesel on 2024-05-31 . MGASA-2024-0233 - Updated chromium-browser-stable packages fix security vulnerabilities Publication date: 24 Jun 2024 URL: https://advisories.mageia.org/MGASA-2024-0233.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-6100, CVE-2024-6101, CVE-2024-6102, CVE-2024-6103 High CVE-2024-6100: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n) participating in SSD Secure Disclosure's TyphoonPWN 2024 on 2024-06-04 High CVE-2024-6101: Inappropriate implementation in WebAssembly. Reported by @ginggilBesel on 2024-05-31 High CVE-2024-6102: Out of bounds memory access in Dawn. Reported by wgslfuzz on 2024-05-07 High CVE-2024-6103: Use after free in Dawn. Reported by wgslfuzz on 2024-06-04 References: - https://bugs.mageia.org/show_bug.cgi?id=33321 - https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop_18.html - https://www.cve.org/CVERecord?id=CVE-2024-6100 - https://www.cve.org/CVERecord?id=CVE-2024-6101 - https://www.cve.org/CVERecord?id=CVE-2024-6102 - https://www.cve.org/CVERecord?id=CVE-2024-6103 SRPMS: - 9/tainted/chromium-browser-stable-126.0.6478.114-1.mga9.tainted . Recent updates to the chromium-browser-stable packages in Mageia have resolved significant security vulnerabilities with effective patches.. chromium updates, mageia security, type confusion, memory access. . LinuxSecurity.com Team

Calendar%202 Jun 24, 2024 Mageia
89

Fedora 38: 2024-b4dab205d7 critical: chromium multiple security fixes

update to 123.0.6312.86 Critical CVE-2024-2883: Use after free in ANGLE High CVE-2024-2885: Use after free in Dawn High CVE-2024-2886: Use after free in WebCodecs High CVE-2024-2887: Type Confusion in WebAssembly. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b4dab205d7 2024-03-29 02:39:36.209178 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 38 Version : 123.0.6312.86 Release : 1.fc38 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: update to 123.0.6312.86 Critical CVE-2024-2883: Use after free in ANGLE High CVE-2024-2885: Use after free in Dawn High CVE-2024-2886: Use after free in WebCodecs High CVE-2024-2887: Type Confusion in WebAssembly -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 27 2024 Than Ngo - 123.0.6312.86-2 - update to 123.0.6312.86 * Critical CVE-2024-2883: Use after free in ANGLE * High CVE-2024-2885: Use after free in Daw * High CVE-2024-2886: Use after free in WebCodecs * High CVE-2024-2887: Type Confusion in WebAssembly -------------------------------------------------------------------------------- References: [ 1 ] Bug #2271851 - CVE-2024-2883 chromium: Use after free in ANGLE [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2271851 [ 2 ] Bug #2271856 - CVE-2024-2885 chromium: Use after free in Dawn [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2271856 [ 3 ] Bug #2271862 - CVE-2024-2886 chromium: Use after free in WebCodecs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2271862 [ 4 ] Bug #2271868 -CVE-2024-2887 chromium: Type Confusion in WebAssembly [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2271868 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b4dab205d7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Learn about critical updates for Chromium in Fedora 38, addressing multiple security issues and enhancements.. Fedora Security, Chromium Update, Linux Browser Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 29, 2024 Critical Fedora
89

Fedora 38: FEDORA-2023-ab291ca614 Critical: Wabt Software Update

Latest stable release. Full upstream changelog: https://github.com/WebAssembly/wabt/compare/1.0.32...1.0.33 . Fixes CVE-2023-27116, CVE-2023-30300 and CVE-2023-31669.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-ab291ca614 2023-06-26 00:40:45.470173 --------------------------------------------------------------------------------Name : wabt Product : Fedora 38 Version : 1.0.33 Release : 1.fc38 URL : https://github.com/WebAssembly/wabt Summary : The WebAssembly Binary Toolkit Description : WABT (we pronounce it "wabbit") is a suite of tools for WebAssembly. These tools are intended for use in (or for development of) toolchains or other systems that want to manipulate WebAssembly files. Unlike the WebAssembly spec interpreter (which is written to be as simple, declarative and "speccy" as possible), they are written in C/C++ and designed for easier integration into other systems. Unlike Binaryen these tools do not aim to provide an optimization platform or a higher-level compiler target; instead they aim for full fidelity and compliance with the spec (e.g. 1:1 round-trips with no changes to instructions). --------------------------------------------------------------------------------Update Information: Latest stable release. Full upstream changelog: https://github.com/WebAssembly/wabt/compare/1.0.32...1.0.33 . Fixes CVE-2023-27116, CVE-2023-30300 and CVE-2023-31669. --------------------------------------------------------------------------------ChangeLog: * Thu May 25 2023 Dominik Mierzejewski 1.0.33-1 - update to 1.0.33 (#2203483) - drop obsolete patch - disable failing tests on aarch64 and ppc64le (reported upstream) - fix running tests on i686 - disable failing wasm2c tests on s390x (big endian not supported upstream) - fix deprecated patchN macro usage * Sat Jan 21 2023 Fedora Release Engineering - 1.0.32-2 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2171755 - wabt: FTBFS in Fedora rawhide/f38 https://bugzilla.redhat.com/show_bug.cgi?id=2171755 [ 2 ] Bug #2179300 - CVE-2023-27116 wabt: webassembly: an abort in CWriter::MangleType. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2179300 [ 3 ] Bug #2193028 - CVE-2023-30300 wabt: wasm2c hangs on certain inputs and cannot finish execution for a while [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2193028 [ 4 ] Bug #2203483 - wabt-1.0.33 is available https://bugzilla.redhat.com/show_bug.cgi?id=2203483 [ 5 ] Bug #2209423 - CVE-2023-31669 wabt: Crash in libc++abi.dylib [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2209423 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ab291ca614' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 38 has launched with a crucial update for wabt 1.0.33, fixingsecurity vulnerabilities and enhancing the WebAssembly toolkit's functionality. WebAssembly Toolkit, Fedora Security Update, wabt CVE Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 26, 2023 Critical Fedora
203

Mageia: 2022-0487 Critical: Python-Ujson Len Overflow Issue Fix

Fixes len integer overflow issue. (RHBZ#2149975) Ultrajson doesn't build on webassembly (e.g. pyodide) because the version of double-conversion used is too old. This updates it to a newer version which supports webassembly. . MGASA-2022-0487 - Updated python-ujson packages fix security vulnerability Publication date: 30 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0487.html Type: security Affected Mageia releases: 8 Fixes len integer overflow issue. (RHBZ#2149975) Ultrajson doesn't build on webassembly (e.g. pyodide) because the version of double-conversion used is too old. This updates it to a newer version which supports webassembly. References: - https://bugs.mageia.org/show_bug.cgi?id=31332 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/MJ66UZLJXIEOD5Q74IZKQQRWAPPFG6T7/ - https://github.com/ultrajson/ultrajson/pull/570 SRPMS: - 8/core/python-ujson-5.6.0-1.mga8 . Revised python-ujson libraries in Mageia address length overflow concern and enhance compatibility with webassembly.. python-ujson, mageia update, len overflow fix, webassembly support. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 30, 2022 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200