Critical Linux Security Update: Kernel, Django, And Bind Issues
Greetings, fellow Linux users! Your security is our top concern, so we want to alert you to some critical updates you should know about. Multiple dangerous security vulnerabilities have been found in the Linux kernel, which are easy to exploit and pose a severe risk to the security of your firewall as well as your system's confidentiality, integrity, and availability. Don't get caught off guard! These bugs can cause system crashes and privilege escalation attacks.
We also have other significant discoveries and fixes for you, including a ReDoS bug fixed in Django that could result in loss of system access and potential compromise and a remotely exploitable security issue in the Bind Internet Domain Name Server that a remote attacker could possibly exploit to cause a denial of service. It's essential that you stay up-to-date on these issues to protect your system from any potential harm.
We know that cybersecurity threats can be daunting, but we're here to make it easy for you. By updating your system now, you'll take the first step in securing your system and preventing future breaches. Stay ahead of the game by reading on to learn more about these critical threats and the actions you need to take to remain safe and secure.
Also, be sure to check out our Linux security analysis with industry experts to gain critical insights into the past, present, and future of Linux security.
Yours in Open Source,

Linux KernelThe DiscoveryMultiple significant security vulnerabilities have been discovered in the Linux kernel, including a remotely exploitable null pointer dereference flaw in the networking protocol (CVE-2023-3338), use-after-free vulnerabilities in kernel's netfilter subsystem in net/netfilter/nf_tables_api.c (CVE-2023-3390) and nft_chain_lookup_byid() (CVE-2023-31248), and an out-of-bounds read/write vulnerability (CVE-2023-35001). These bugs are easy to exploit and pose a severe risk to the security of your firewall and your system's confidentiality, integrity, and availability. As a result, they have received a National Vulnerability Database severity rating of “High”. |
DjangoThe DiscoveryDistros continue to release updates for a severe ReDoS (regular expression denial of service) vulnerability found in EmailValidator and URLValidator in Django before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3 (CVE-2023-36053). |
BindThe DiscoveryDistros also continue to release updates addressing a remotely exploitable security issue in the Bind Internet Domain Name Server. It was discovered that Bind incorrectly handled the cache size limit (CVE-2023-2828). This bug is simple to exploit and poses a significant risk to the availability of your systems. As a result, it has received a National Vulnerability Database severity rating of “High”. |



