Linux admins -

Critical updates were just released to Debian 12 that improve the security of the most significant apps we use, like OpenSSL, nginx, and the kernel itself. Admins maintaining production servers or personal systems can greatly benefit from applying this update. From its critical security fixes addressing vulnerabilities like buffer overflows and XSS vulns to bug fixes to PHP and ghostscript, all of us should expect a much more secure and reliable release.

You'll also learn about a Branch Privilege Injection flaw threatening Intel processors that allows attackers to access kernel data or extract sensitive information from virtual machines.

If you found value in today’s newsletter, please share it with your friends! Do you have a Linux security-related topic you'd like to cover for our audience? We welcome contributions from passionate and insightful community members who share our love for Linux and security.

Yours in Open Source, 

Dv Signature Newsletter 2024 Esm W150

Dave Wreski

LinuxSecurity Founder

Debian 12

The Discovery 

Debian has identified critical flaws in widely used apps, including OpenSSL, nginx, and the kernel itself. These issues include buffer overflows and XSS bugs.

Debian Esm W179

The Impact

These vulnerabilities could result in crashes, exploits, and disruptions to your workflows.

 The Fix

Debian 12.11 has been released to address these critical flaws. All Debian users should update immediately to safeguard their systems and prevent downtime.

Your Related Advisories:

[distro_list_1]

Intel Processors 

The Discovery 

Branch Privilege Injection flaw threatening Intel processors (CVE-2024-45332) has been discovered. By exploiting this vulnerability, attackers can access arbitrary memory and read sensitive data stored outside their privilege domain.

Intel Microcode Esm W224

The Impact

This bug allows attackers to access kernel data or extract sensitive information from virtual machines.

 The Fix

Intel has released critical updates to address this issue. It is essential that all impacted admins update immediately to safeguard their systems and sensitive data.

Your Related Advisories:

[distro_list_2]