Security 10919 Published by

Several Linux distributions have received security updates over the past week, addressing vulnerabilities in various packages such as MariaDB, SSSD, GnuPG2, libidn2, and FFmpeg. The affected distributions include AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux. These updates aim to improve the security of the operating systems by addressing various vulnerabilities that could result in denial of service or arbitrary code execution. These security updates have impacted multiple versions of these distributions, including AlmaLinux 8, 9, and 10 and Oracle Linux 7, 8, and 9.





AlmaLinux

AlmaLinux users have received security update emails regarding MariaDB, a database server that's compatible with MySQL, to address various security issues and prevent remote code execution vulnerabilities. This update is one of several recent notifications sent out by the AlmaLinux team, highlighting their efforts to keep the operating system secure. In addition to MariaDB, AlmaLinux has also released updates for System Security Services Daemon (SSSD) and GnuPG2; a critical vulnerability in the latter could lead to information disclosure or code execution. These security updates are available for multiple versions of AlmaLinux, including 8, 9, and 10.

Debian GNU/Linux

Debian has released security updates to address vulnerabilities in various packages. These updates include fixes for libidn2, which allowed attackers to impersonate other domains through carefully crafted domain names, and Net-SNMP. The updates also cover a range of other software, such as Linux, Chromium, GnuPG2, and Firefox. In addition, Debian has released security updates for FFmpeg and Python-urllib3 to address vulnerabilities that could result in denial of service or arbitrary code execution.

Fedora Linux

Fedora 42 and Fedora 43 have received updates to address security vulnerabilities. The patches include fixes for several issues in Chromium's WebView tag and MuseScore's FluidSynth software synthesizer. Additionally, other packages such as NetworkManager-l2tp, Composer, and Python3 have been updated with security patches. These updates aim to ensure the operating system remains secure and up-to-date by addressing various vulnerabilities.

Oracle Linux

Oracle has released several security updates for its Linux distributions, affecting various versions of Oracle Linux, including 7, 8, and 9. The company has also provided updates for specific components such as the kernel, OpenSSL, Dracut, and Device-Mapper across different versions of Oracle Linux. In addition to these updates, Oracle has released fixes for other critical components like Podman, PostgreSQL, Unbreakable Enterprise kernel, and more. These security patches aim to address vulnerabilities in packages like .NET and GnuPG2 and are available for various versions of Oracle Linux, including 8, 9, and 10.

Red Hat Enterprise Linux

Red Hat Enterprise Linux has received multiple security updates across various packages. The affected packages include the kernel, libssh, Wireshark, runc, buildah, and libsoup. These updates aim to address vulnerabilities and improve the overall security of RHEL systems. Multiple versions of Red Hat Enterprise Linux have been impacted by these security updates, including RHEL 10 for some of them.

Rocky Linux

Multiple security updates are available for Rocky Linux 8 and 9, addressing vulnerabilities in various packages. These updates include patches for pam (important), postgresql16, postgresql, libpq, cups, and other packages. Additional security updates have been released for several other packages, including libsoup3, libpg, buildah, vsftpd, Firefox, MariaDB, gnupg2, podman, and net-snmp. The updates affect different versions of Rocky Linux, including 8, 9, and 10, addressing vulnerabilities that can be found on the CVE list along with their corresponding CVSS base scores.

Slackware Linux

Security updates are available for Mozilla Firefox, libpng, and Mozilla Thunderbird on Slackware 15.0 and -current. These updates fix security issues, including heap buffer over-reads and integer truncation errors. The patches address vulnerabilities in the mentioned software to prevent potential security threats.

SUSE Linux

Multiple security update releases have been made available for SUSE Linux, addressing various vulnerabilities and concerns. The updates include fixes for packages such as util-linux, libpng16, ovmf, podman, poppler, tomcat, libwireshark19, avahi, python311-virtualenv, NetworkManager-applet-l2tp, Mozilla Thunderbird, Chromium, Erlang, Alloy, and Bind. These updates aim to improve the security and stability of SUSE Linux systems. The releases also include important fixes for other packages like kernel-devel, mcphost, fluidsynth, firefox-esr, libsoup-3_0-0, gpg2, curl, squid, apache2, hawk2, python311-urllib3, and NetworkManager-applet-l2tp.

Ubuntu Linux

Ubuntu has released several security updates to address various vulnerabilities in its packages. The affected software includes libheif, which had a security issue that could allow an attacker to cause a denial of service or execute arbitrary code on Ubuntu 20. Additionally, other updates have been issued for Libtasn1, Python, PHP, urllib3, Google Guest Agent, WebKitGTK, urllib3, AngularJS, Erlang, Klibc, Libpng, Rack, CPP-Httplib, Python-APT, Git, and SimGear across multiple Ubuntu releases. These updates aim to fix vulnerabilities and address security concerns in various packages used by the operating system.

Tuxrepair