[ GLSA 202511-07 ] librnp: Weak random number generation
A security advisory has been issued for Gentoo Linux, warning users about a vulnerability in the librnp package due to weak random number generation that can be easily cracked. The affected version of librnp, 0.18.0, generates weak session keys for public key encryption, potentially allowing attackers with just the public key to read encrypted messages. Users are advised to upgrade to the latest version of librnp (0.18.1 or higher) as soon as possible and be aware that sensitive information sent using affected software may have been compromised.
[ GLSA 202511-07 ] librnp: Weak random number generation
[ GLSA 202511-07 ] librnp: Weak random number generation
Gentoo Linux has released security updates to address multiple vulnerabilities in various packages. The affected packages include UDisks, WebKitGTK+, qtsvg, Chromium, and Redis.
[ GLSA 202511-01 ] UDisks: Multiple Vulnerabilities
[ GLSA 202511-02 ] WebKitGTK+: Multiple Vulnerabilities
[ GLSA 202511-03 ] qtsvg: Multiple Vulnerabilities
[ GLSA 202511-04 ] Chromium, Google Chrome, Microsoft Edge. Opera: Multiple Vulnerabilities
[ GLSA 202511-05 ] redict, redis: Multiple Vulnerabilities
[ GLSA 202511-01 ] UDisks: Multiple Vulnerabilities
[ GLSA 202511-02 ] WebKitGTK+: Multiple Vulnerabilities
[ GLSA 202511-03 ] qtsvg: Multiple Vulnerabilities
[ GLSA 202511-04 ] Chromium, Google Chrome, Microsoft Edge. Opera: Multiple Vulnerabilities
[ GLSA 202511-05 ] redict, redis: Multiple Vulnerabilities
Gentoo Linux has been updated with several security vulnerabilities, including Composer, Spreadsheet-ParseExcel, Mozilla Network Security Service, FontForge, GPL Ghostscript, and PAM:
[ GLSA 202508-06 ] Composer: Multiple Vulnerabilities
[ GLSA 202508-05 ] Spreadsheet-ParseExcel: Arbitrary Code Execution
[ GLSA 202508-04 ] Mozilla Network Security Service (NSS): TLS RSA decryption timing attack
[ GLSA 202508-03 ] FontForge: Arbitrary Code Execution
[ GLSA 202508-02 ] GPL Ghostscript: Multiple Vulnerabilities
[ GLSA 202508-01 ] PAM: Multiple Vulnerabilities
[ GLSA 202508-06 ] Composer: Multiple Vulnerabilities
[ GLSA 202508-05 ] Spreadsheet-ParseExcel: Arbitrary Code Execution
[ GLSA 202508-04 ] Mozilla Network Security Service (NSS): TLS RSA decryption timing attack
[ GLSA 202508-03 ] FontForge: Arbitrary Code Execution
[ GLSA 202508-02 ] GPL Ghostscript: Multiple Vulnerabilities
[ GLSA 202508-01 ] PAM: Multiple Vulnerabilities
A Roundcube security update is available for Gentoo Linux:
[ GLSA 202507-10 ] Roundcube: Multiple Vulnerabilities
[ GLSA 202507-10 ] Roundcube: Multiple Vulnerabilities
Gentoo Linux has received multiple security updates addressing vulnerabilities in ClamAV, strongSwan, NTP, Git, Chromium, and REXML:
[ GLSA 202507-03 ] ClamAV: Multiple Vulnerabilities
[ GLSA 202507-04 ] strongSwan: Buffer Overflow
[ GLSA 202507-05 ] NTP: Multiple Vulnerabilities
[ GLSA 202507-09 ] Git: Multiple Vulnerabilities
[ GLSA 202507-07 ] Chromium, Google Chrome, Microsoft Edge. Opera: Multiple Vulnerabilities
[ GLSA 202507-08 ] REXML: Multiple Vulnerabilities
[ GLSA 202507-03 ] ClamAV: Multiple Vulnerabilities
[ GLSA 202507-04 ] strongSwan: Buffer Overflow
[ GLSA 202507-05 ] NTP: Multiple Vulnerabilities
[ GLSA 202507-09 ] Git: Multiple Vulnerabilities
[ GLSA 202507-07 ] Chromium, Google Chrome, Microsoft Edge. Opera: Multiple Vulnerabilities
[ GLSA 202507-08 ] REXML: Multiple Vulnerabilities
Gentoo Linux has received security updates for Konsole and Sysstat:
[ GLSA 202506-13 ] Konsole: Code execution
[ GLSA 202506-12 ] sysstat: Arbitrary Code Execution
[ GLSA 202506-13 ] Konsole: Code execution
[ GLSA 202506-12 ] sysstat: Arbitrary Code Execution
The latest security updates for Gentoo Linux include YAML-LibYAML, File-Find-Rule, OpenImageIO, Node.js, Python, PyPy, Qt, GTK+ 3, X.Org X server, XWayland, LibreOffice, GStreamer, GStreamer Plugins, and Emacs, addressing various vulnerabilities:
[ GLSA 202506-11 ] YAML-LibYAML: Shell injection
[ GLSA 202506-10 ] File-Find-Rule: Shell Injection
[ GLSA 202506-09 ] OpenImageIO: Multiple Vulnerabilities
[ GLSA 202506-08 ] Node.js: Multiple Vulnerabilities
[ GLSA 202506-07 ] Python, PyPy: Multiple Vulnerabilities
[ GLSA 202506-06 ] Qt: Multiple Vulnerabilities
[ GLSA 202506-05 ] GTK+ 3: Search path vulnerability
[ GLSA 202506-04 ] X.Org X server, XWayland: Multiple Vulnerabilities
[ GLSA 202506-03 ] LibreOffice: Multiple Vulnerabilities
[ GLSA 202506-02 ] GStreamer, GStreamer Plugins: Multiple Vulnerabilities
[ GLSA 202506-01 ] Emacs: Multiple Vulnerabilities
[ GLSA 202506-11 ] YAML-LibYAML: Shell injection
[ GLSA 202506-10 ] File-Find-Rule: Shell Injection
[ GLSA 202506-09 ] OpenImageIO: Multiple Vulnerabilities
[ GLSA 202506-08 ] Node.js: Multiple Vulnerabilities
[ GLSA 202506-07 ] Python, PyPy: Multiple Vulnerabilities
[ GLSA 202506-06 ] Qt: Multiple Vulnerabilities
[ GLSA 202506-05 ] GTK+ 3: Search path vulnerability
[ GLSA 202506-04 ] X.Org X server, XWayland: Multiple Vulnerabilities
[ GLSA 202506-03 ] LibreOffice: Multiple Vulnerabilities
[ GLSA 202506-02 ] GStreamer, GStreamer Plugins: Multiple Vulnerabilities
[ GLSA 202506-01 ] Emacs: Multiple Vulnerabilities
Gentoo Linux has been updated with several security vulnerabilities, including Spidermonkey, FreeType, Atop, Node.js, and Tracker miners:
[ GLSA 202505-08 ] Spidermonkey: Multiple Vulnerabilities
[ GLSA 202505-07 ] FreeType: Remote Code Execution
[ GLSA 202505-09 ] Atop: Heap Corruption
[ GLSA 202505-11 ] Node.js: Multiple Vulnerabilities
[ GLSA 202505-10 ] Tracker miners: Sandbox weakness
[ GLSA 202505-08 ] Spidermonkey: Multiple Vulnerabilities
[ GLSA 202505-07 ] FreeType: Remote Code Execution
[ GLSA 202505-09 ] Atop: Heap Corruption
[ GLSA 202505-11 ] Node.js: Multiple Vulnerabilities
[ GLSA 202505-10 ] Tracker miners: Sandbox weakness
Gentoo Linux has received an update addressing various security vulnerabilities, including multiple issues found in PAM, Mozilla Firefox, Mozilla Thunderbird, Orc, NVIDIA Drivers, and glibc:
[ GLSA 202505-01 ] PAM: Multiple Vulnerabilities
[ GLSA 202505-02 ] Mozilla Firefox: Multiple Vulnerabilities
[ GLSA 202505-03 ] Mozilla Thunderbird: Multiple Vulnerabilities
[ GLSA 202505-05 ] Orc: Arbitrary Code Execution
[ GLSA 202505-04 ] NVIDIA Drivers: Multiple Vulnerabilities
[ GLSA 202505-06 ] glibc: Buffer Overflow
[ GLSA 202505-01 ] PAM: Multiple Vulnerabilities
[ GLSA 202505-02 ] Mozilla Firefox: Multiple Vulnerabilities
[ GLSA 202505-03 ] Mozilla Thunderbird: Multiple Vulnerabilities
[ GLSA 202505-05 ] Orc: Arbitrary Code Execution
[ GLSA 202505-04 ] NVIDIA Drivers: Multiple Vulnerabilities
[ GLSA 202505-06 ] glibc: Buffer Overflow
The most recent security update for Gentoo Linux fixes an issue in XZ Utils:
[ GLSA 202504-01 ] XZ Utils: Use after free
[ GLSA 202504-01 ] XZ Utils: Use after free
New OpenSSH packages have been released for Gentoo Linux to resolve several vulnerabilities that may enable a remote attacker to obtain unauthorized access:
[ GLSA 202502-01 ] OpenSSH: Multiple Vulnerabilities
[ GLSA 202502-01 ] OpenSSH: Multiple Vulnerabilities
Updated PHP packages are available for Gentoo Linux:
[ GLSA 202501-11 ] PHP: Multiple Vulnerabilities
[ GLSA 202501-11 ] PHP: Multiple Vulnerabilities
Gentoo Linux has received multiple updates addressing several security vulnerabilities, which include issues in Mozilla Firefox, QtWebEngine, Qt: Buffer Overflow, libgsf, GPL Ghostscript, libuv, and Yubico pam-u2f:
[ GLSA 202501-10 ] Mozilla Firefox: Multiple Vulnerabilities
[ GLSA 202501-09 ] QtWebEngine: Multiple Vulnerabilities
[ GLSA 202501-08 ] Qt: Buffer Overflow
[ GLSA 202501-07 ] libgsf: Multiple Vulnerabilities
[ GLSA 202501-06 ] GPL Ghostscript: Multiple Vulnerabilities
[ GLSA 202501-05 ] libuv: Hostname Truncation
[ GLSA 202501-04 ] Yubico pam-u2f: Partial Authentication Bypass
[ GLSA 202501-10 ] Mozilla Firefox: Multiple Vulnerabilities
[ GLSA 202501-09 ] QtWebEngine: Multiple Vulnerabilities
[ GLSA 202501-08 ] Qt: Buffer Overflow
[ GLSA 202501-07 ] libgsf: Multiple Vulnerabilities
[ GLSA 202501-06 ] GPL Ghostscript: Multiple Vulnerabilities
[ GLSA 202501-05 ] libuv: Hostname Truncation
[ GLSA 202501-04 ] Yubico pam-u2f: Partial Authentication Bypass
Gentoo Linux has been updated with security enhancements, including GLSA 202501-03 addressing arbitrary configuration injection and GLSA 202501-02 which resolves multiple vulnerabilities in GIMP:
[ GLSA 202501-03 ] pip: arbitrary configuration injection
[ GLSA 202501-02 ] GIMP: Multiple Vulnerabilities
[ GLSA 202501-03 ] pip: arbitrary configuration injection
[ GLSA 202501-02 ] GIMP: Multiple Vulnerabilities
New NVIDIA drivers are available for Gentoo Linux to address multiple vulnerabilities that could result in privilege escalation:
[ GLSA 202412-20 ] NVIDIA Drivers: Privilege Escalation
[ GLSA 202412-20 ] NVIDIA Drivers: Privilege Escalation
Gentoo Linux has received updates that include multiple security patches, such as eza, Distrobox, idna, libvirt, and OpenSC, which address a range of vulnerabilities:
[ GLSA 202412-19 ] eza: Arbitrary Code Execution
[ GLSA 202412-18 ] Distrobox: Arbitrary Code Execution
[ GLSA 202412-17 ] idna: Denial of Service
[ GLSA 202412-16 ] libvirt: Multiple Vulnerabilities
[ GLSA 202412-15 ] OpenSC: Multiple Vulnerabilities
[ GLSA 202412-19 ] eza: Arbitrary Code Execution
[ GLSA 202412-18 ] Distrobox: Arbitrary Code Execution
[ GLSA 202412-17 ] idna: Denial of Service
[ GLSA 202412-16 ] libvirt: Multiple Vulnerabilities
[ GLSA 202412-15 ] OpenSC: Multiple Vulnerabilities
Gentoo Linux has received updates focused on security, incorporating enhancements for HashiCorp Consul, Spidermonkey, and PostgreSQL, which mitigate various vulnerabilities:
[ GLSA 202412-14 ] HashiCorp Consul: Multiple Vulnerabilities
[ GLSA 202412-13 ] Spidermonkey: Multiple Vulnerabilities
[ GLSA 202412-12 ] PostgreSQL: Multiple Vulnerabilities
[ GLSA 202412-14 ] HashiCorp Consul: Multiple Vulnerabilities
[ GLSA 202412-13 ] Spidermonkey: Multiple Vulnerabilities
[ GLSA 202412-12 ] PostgreSQL: Multiple Vulnerabilities
The most recent security updates for Gentoo Linux encompass OATH Toolkit, Dnsmasq, Salt, icinga2, OpenJDK, Mozilla Thunderbird, Chromium, Google Chrome, and Microsoft Edge. Opera, Mozilla Firefox, Asterisk, Cacti, Dnsmasq, Salt, icinga2, and R:
[ GLSA 202412-11 ] OATH Toolkit: Privilege Escalation
[ GLSA 202412-10 ] Dnsmasq: Multiple Vulnerabilities
[ GLSA 202412-09 ] Salt: Multiple Vulnerabilities
[ GLSA 202412-08 ] icinga2: Multiple Vulnerabilities
[ GLSA 202412-07 ] OpenJDK: Multiple Vulnerabilities
[ GLSA 202412-06 ] Mozilla Thunderbird: Multiple Vulnerabilities
[ GLSA 202412-05 ] Chromium, Google Chrome, Microsoft Edge. Opera: Multiple Vulnerabilities
[ GLSA 202412-04 ] Mozilla Firefox: Multiple Vulnerabilities
[ GLSA 202412-03 ] Asterisk: Multiple Vulnerabilities
[ GLSA 202412-02 ] Cacti: Multiple Vulnerabilities
[ GLSA 202412-01 ] R: Arbitrary Code Execution
[ GLSA 202412-11 ] OATH Toolkit: Privilege Escalation
[ GLSA 202412-10 ] Dnsmasq: Multiple Vulnerabilities
[ GLSA 202412-09 ] Salt: Multiple Vulnerabilities
[ GLSA 202412-08 ] icinga2: Multiple Vulnerabilities
[ GLSA 202412-07 ] OpenJDK: Multiple Vulnerabilities
[ GLSA 202412-06 ] Mozilla Thunderbird: Multiple Vulnerabilities
[ GLSA 202412-05 ] Chromium, Google Chrome, Microsoft Edge. Opera: Multiple Vulnerabilities
[ GLSA 202412-04 ] Mozilla Firefox: Multiple Vulnerabilities
[ GLSA 202412-03 ] Asterisk: Multiple Vulnerabilities
[ GLSA 202412-02 ] Cacti: Multiple Vulnerabilities
[ GLSA 202412-01 ] R: Arbitrary Code Execution
Gentoo Linux has been updated with security patches addressing several vulnerabilities in Perl, X.Org X server, XWayland, and Pillow, which could lead to arbitrary code execution:
[ GLSA 202411-09 ] Perl: Multiple Vulnerabilities
[ GLSA 202411-08 ] X.Org X server, XWayland: Multiple Vulnerabilities
[ GLSA 202411-07 ] Pillow: Arbitrary code execution
[ GLSA 202411-09 ] Perl: Multiple Vulnerabilities
[ GLSA 202411-08 ] X.Org X server, XWayland: Multiple Vulnerabilities
[ GLSA 202411-07 ] Pillow: Arbitrary code execution