Linux admins -

A web browser is one of those indispensable apps we use on Linux every day, which perhaps also explains why it's such a big target for threat actors and cyber thieves. You know it's bad when, despite all the scrutiny Chrome receives every week, a flaw so stealthy that it went undiscovered for more than twenty years is found.

Learn more about how the black hats can exploit a major privacy vulnerability in our browser history without our permission. This latest release also includes a heap buffer overflow, as well as DevTool weaknesses that could compromise the integrity of your system. 

You'll also learn about recent tweaks to the ublk driver in the kernel that could lead to potential instability, crashes, or data corruption if these issues are left unattended.

If you found value in today’s newsletter, please share it with your friends! Do you have a Linux security-related topic you'd like to cover for our audience? We welcome contributions from passionate and insightful community members who share our love for Linux and security.

Yours in Open Source, 

Dv Signature Newsletter 2024 Esm W150

Dave Wreski

LinuxSecurity Founder

Chrome

The Discovery 

A 20-year browser history privacy flaw, along with a heap buffer overflow and DevTool weaknesses, was recently discovered in Google Chrome.

Chrome Esm W112

The Impact

These issues could enable malicious actors to track and profile without your permission and compromise system integrity.

 The Fix

Chrome 136 fixes these dangerous privacy and security flaws. All affected admins should apply these updates immediately to protect their systems and safeguard the privacy of their web browsing activities.

Your Related Advisories:

[distro_list_1]

Linux Kernel

The Discovery 

Linux 6.15-rc3 has been released with incremental fixes for improved security and stability. These fixes include tweaks to the ublk driver to address long-standing issues. 

LinuxKernel Esm W206

The Impact

These patches protect against potential instability, crashes, or data corruption if these issues are left unattended.

 The Fix

Linux 6.15-rc3 has been released to patch these ublk driver issues, along other security bugs. All admins should update now to secure their sensitive data and ensure their critical systems remain operational.

Your Related Advisories:

[distro_list_2]