Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1243226 Cross-References: * CVE-2025-6019 . # Security update for libblockdev Announcement ID: SUSE-SU-2025:20440-1 Release Date: 2025-06-18T08:51:18Z Rating: moderate References: * bsc#1243226 Cross-References: * CVE-2025-6019 CVSS scores: * CVE-2025-6019 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6019 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-6019 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libblockdev fixes the following issues: * CVE-2025-6019: Suppress privilege escalation during xfs fs resize ( (bsc#1243226) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-150=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libbd_utils2-2.28-slfo.1.1_2.1 * libbd_fs2-2.28-slfo.1.1_2.1 * libblockdev-debugsource-2.28-slfo.1.1_2.1 * libbd_part2-2.28-slfo.1.1_2.1 * libbd_fs2-debuginfo-2.28-slfo.1.1_2.1 * libbd_mdraid2-2.28-slfo.1.1_2.1 * libblockdev2-2.28-slfo.1.1_2.1 * libblockdev-debuginfo-2.28-slfo.1.1_2.1 * libbd_crypto2-2.28-slfo.1.1_2.1 * libbd_lvm2-2.28-slfo.1.1_2.1 * libbd_loop2-debuginfo-2.28-slfo.1.1_2.1 * libbd_lvm2-debuginfo-2.28-slfo.1.1_2.1 * libbd_btrfs2-debuginfo-2.28-slfo.1.1_2.1 * libbd_utils2-debuginfo-2.28-slfo.1.1_2.1 * libbd_loop2-2.28-slfo.1.1_2.1 * libblockdev2-debuginfo-2.28-slfo.1.1_2.1 * libbd_mdraid2-debuginfo-2.28-slfo.1.1_2.1 * libbd_crypto2-debuginfo-2.28-slfo.1.1_2.1 * libbd_swap2-2.28-slfo.1.1_2.1 * libbd_part2-debuginfo-2.28-slfo.1.1_2.1 *libbd_swap2-debuginfo-2.28-slfo.1.1_2.1 * libbd_btrfs2-2.28-slfo.1.1_2.1 * libblockdev-2.28-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6019.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . SUSE Linux Micro 6.1 has released a security patch to tackle a moderate vulnerability found in libblockdev, aimed at mitigating potential privilege escalation threats.. SUSE Linux Micro, libblockdev, security update, privilege escalation, software patch. . LinuxSecurity.com Team
An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2022:0530-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:0530 Issue date: 2022-02-15 CVE Names: CVE-2021-4155 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.4) - noarch, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.4) - x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: xfs: raw block device data leak in XFS_IOC_ALLOCSP IOCTL (CVE-2021-4155) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2034813 - CVE-2021-4155 kernel: xfs: raw block device data leak in XFS_IOC_ALLOCSP IOCTL 6.Package List: Red Hat Enterprise Linux Server AUS (v. 7.4): Source: kernel-3.10.0-693.96.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-693.96.1.el7.noarch.rpm kernel-doc-3.10.0-693.96.1.el7.noarch.rpm x86_64: kernel-3.10.0-693.96.1.el7.x86_64.rpm kernel-debug-3.10.0-693.96.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-693.96.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-693.96.1.el7.x86_64.rpm kernel-devel-3.10.0-693.96.1.el7.x86_64.rpm kernel-headers-3.10.0-693.96.1.el7.x86_64.rpm kernel-tools-3.10.0-693.96.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-693.96.1.el7.x86_64.rpm perf-3.10.0-693.96.1.el7.x86_64.rpm perf-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm python-perf-3.10.0-693.96.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.4): x86_64: kernel-debug-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-693.96.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-693.96.1.el7.x86_64.rpm perf-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-693.96.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-4155 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYgvWa9zjgjWX9erEAQi8Lw//f7o5XQ23uw6MPDgZj8pjZH6eKiuzsmT2 1yMsdljXoUFrH8EUs4jag/WKuw/PNY/reZFAv+uHH1MRBYwRp10OEoGHbTdq5FFs ZzoOnLJWUVZMRfx8/GUNv3pmYfUc3bbgzeFSuX4KHgXH12oqLLnT/nbQUtoDbWL1 FEVSrqfa3oMr+NOD82ZF2D+yCQGjpq7SFjym7MP/D8VyKm4YdKFd6ISzcgjCF3c1 lRs64z4AuXuH0mFt7FJfO2o0iP8sI8KNGDJffgAVjBDi04ML69lyLUO7yr//zf6d 8UEXYo0lVuR0BB2O31P8B7QtT8P+HfZfleGdkdExqx9+WDhP2y9Ta9NhHXOG7L1C cyuONSt5qii9GRH/TlWPHukyFJXV+8Tfa6OQopY8DHfRAt5AbULGPU9YKfwYfr+n pwhvVz2deAcdQ9uHBEyV1LoLk+1lsvBLWDVIufGzP9aPIHUDFtyMa5vRz71ws5k9 m1dKB9dsne5aOE256FSucNUdeNY3YnUJGxp2o9VaJQcVag0o0Nl7L3Ex5z2WuVh9 Fu4YSB4vWXRkVWhDV8ic96WJnX3EJrM3iVC6fj8KWRbAJTt4SylE1pY5wFcDfVpP UhfG6GuCD/AVMuURPZicTJUaMr9jbL8AR8GOnPXuBQvCHD5kRF343ZGw2rbDHGus Z80Q+HnsqAQ=hirW -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-1975-1 September 27, 2013 linux-ti-omap4 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 Summary: Several security issues were fixed in the kernel. Software Description: - linux-ti-omap4: Linux kernel for OMAP4 Details: Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on ARM platforms. A local user could exploit this flaw to gain privileges or cause a denial of service (system crash). (CVE-2013-4254) A failure to validate block numbers was discovered in the Linux kernel's implementation of the XFS filesystem. A local user can cause a denial of service (system crash) if they can mount, or cause to be mounted a corrupted or special crafted XFS filesystem. (CVE-2013-1819) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: linux-image-3.5.0-233-omap4 3.5.0-233.49 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-1975-1 CVE-2013-1819, CVE-2013-4254 Package Information: https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-233.49 . Debian SecurityAdvisory DSA-2678-1 outlines vulnerabilities related to the Linux kernel impacting ARM architecture, along with corresponding fixes and enhancements.. Ubuntu Kernel Security,Patch Management,OMAP4 Threats. . LinuxSecurity.com Team
It was discovered that a race condition in the init.d script of the X Font Server allows the modification of file permissions of arbitrary files if the local administrator can be tricked into restarting the X font server.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1342-1
Updated X.org packages that address a flaw in the way the X.Org X11 xfs font server starts are now available for Red Hat Enterprise Linux 5.A temporary file flaw was found in the way the X.Org X11 xfs font server startup script executes. A local user could modify the permissions of a file of their choosing, possibly elevating their local privileges. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: xorg-x11-xfs security update Advisory ID: RHSA-2007:0520-01 Advisory URL: https://access.redhat.com/errata/RHSA-2007:0520.html Issue date: 2007-07-12 Updated on: 2007-07-12 Product: Red Hat Enterprise Linux CVE Names: CVE-2007-3103 - ---------------------------------------------------------------------1. Summary: Updated X.org packages that address a flaw in the way the X.Org X11 xfs font server starts are now available for Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Problem description: The X.Org X11 xfs font server provides a standard mechanism for an X server to communicate with a font renderer. A temporary file flaw was found in the way the X.Org X11 xfs font server startup script executes. A local user could modify the permissions of a file of their choosing, possibly elevating their local privileges. (CVE-2007-3103) Users of the X.org X11 xfs font server should upgrade to these updated packages, which contain a backported patch and are not vulnerable to this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant toyour system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bug IDs fixed (http://bugzilla.redhat.com/): 242903 - CVE-2007-3103 init.d xfs script chown race condition vulnerability 6. RPMs required: Red Hat Enterprise Linux Desktop (v. 5 client): SRPMS: 7f6d90098c6a752c16894315b85e739e xorg-x11-xfs-1.0.2-4.src.rpm i386: 94318ae2d5f02439c58541c5a9c34314 xorg-x11-xfs-1.0.2-4.i386.rpm 8880bbe448c5d423e2056800b56e3636 xorg-x11-xfs-debuginfo-1.0.2-4.i386.rpm 1e54d7037ede3c1a5476d3ad65b62eb0 xorg-x11-xfs-utils-1.0.2-4.i386.rpm x86_64: 434fb4f47152e671d0c59b9b677295a8 xorg-x11-xfs-1.0.2-4.x86_64.rpm 091aefa331d43036745b55d90c59a4b4 xorg-x11-xfs-debuginfo-1.0.2-4.x86_64.rpm 6cea61c7098202810b812aba74e8610c xorg-x11-xfs-utils-1.0.2-4.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): SRPMS: 7f6d90098c6a752c16894315b85e739e xorg-x11-xfs-1.0.2-4.src.rpm i386: 94318ae2d5f02439c58541c5a9c34314 xorg-x11-xfs-1.0.2-4.i386.rpm 8880bbe448c5d423e2056800b56e3636 xorg-x11-xfs-debuginfo-1.0.2-4.i386.rpm 1e54d7037ede3c1a5476d3ad65b62eb0 xorg-x11-xfs-utils-1.0.2-4.i386.rpm ia64: 9657c080a0362243369a9b54f5207851 xorg-x11-xfs-1.0.2-4.ia64.rpm 1ae3c7834e7e591c3e13b8babb1f9485 xorg-x11-xfs-debuginfo-1.0.2-4.ia64.rpm 346da7e5c6d4660d510016d44fabc095 xorg-x11-xfs-utils-1.0.2-4.ia64.rpm ppc: 2a140017df1fefae7828547975f0d48a xorg-x11-xfs-1.0.2-4.ppc.rpm 8eb1e6ded2137a78a7258d16f823f2bd xorg-x11-xfs-debuginfo-1.0.2-4.ppc.rpm 703f21661da66e60c38a2356643078f6 xorg-x11-xfs-utils-1.0.2-4.ppc.rpm s390x: faaacf77fde117b6c71afcb60c7c9508 xorg-x11-xfs-1.0.2-4.s390x.rpm 4a56c7298da2c1ece7ce05a076989637 xorg-x11-xfs-debuginfo-1.0.2-4.s390x.rpm 86b097cc09ab2ab9a7687755950b7279 xorg-x11-xfs-utils-1.0.2-4.s390x.rpm x86_64: 434fb4f47152e671d0c59b9b677295a8 xorg-x11-xfs-1.0.2-4.x86_64.rpm 091aefa331d43036745b55d90c59a4b4 xorg-x11-xfs-debuginfo-1.0.2-4.x86_64.rpm 6cea61c7098202810b812aba74e8610c xorg-x11-xfs-utils-1.0.2-4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2007-3103 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2007 Red Hat, Inc. . This patch resolves a significant vulnerability in the xfs font server within Red Hat, bolstering overall cybersecurity.. Red Hat, X.Org, XFS Server, Security Update, System Protection. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.