Security 10907 Published by

Here is a roundup of last week's security updates for several Linux distributions, including AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux, which have released security updates to address vulnerabilities in various packages. The updates range from moderate to important severity and affect packages such as the kernel, webkit2gtk3, libssh, Firefox, OpenSSL, and others, resolving issues like integer overflow, use-after-free bugs, privilege escalation, denial of service, and remote code execution. Users are advised to apply these security updates to ensure the stability and security of their systems, with some distributions providing detailed severity ratings through the Common Vulnerability Scoring System (CVSS) base score.





AlmaLinux

AlmaLinux has released several security updates to address vulnerabilities in various packages. The updates include patches for iputils, open-vm-tools, libtiff3, and vim, which resolve issues such as integer overflow and use-after-free bugs. Additionally, updates have been released for the kernel, webkit2gtk3, libsoup3, and libssh, which fix vulnerabilities affecting HID, eventpoll, ALSA, crypto, and sftp_handle() components. The severity of these updates ranges from moderate to important, indicating a significant risk if left unpatched.

Debian GNU/Linux

Debian has released several security updates to address vulnerabilities in various packages, including the Linux kernel, libfcgi, ghostscript, Distro-Info, HTTPS-Everywhere, Horde, Intel-Microcode, QEMU, Firefox, LibXML, and more. These updates affect different versions of Debian GNU/Linux, including Bullseye LTS, Bookworm, and Trixie. The vulnerabilities addressed in these updates include privilege escalation, denial of service, information leaks, remote code execution, and null pointer dereferences. Users are advised to apply the security updates to ensure the stability and security of their systems.

Fedora Linux

Security updates have been released for Fedora Linux versions 41 and 42, addressing various vulnerabilities in packages such as Python, OpenSSL, podman-related tools, and Apache HTTP Server (httpd). Additionally, updates have been made available for several other packages, including Firefox, MinGW, Fetchmail, and qt5-qtsvg, which provides support for rendering SVG on Fedora systems. The updates aim to improve the security and stability of Fedora Linux by addressing potential vulnerabilities and bug fixes. Fedora 42 has also received updates to its Python versions (3.9, 3.10, and 3.11) that address specific security vulnerabilities.

Oracle Linux

Oracle has released security updates for various versions of its Linux distributions, including Oracle Linux 8, 7, 9, and 10. The updates address vulnerabilities in packages such as the kernel, webkit2gtk3, gnutls, vim, nodejs, and pki-deps. In addition to these security patches, Oracle has also released bug fixes for other components like systemd, mcelog, and scap-security-guide. These updates are available for various versions of Oracle Linux, including 7, 8, 9, and 10.

Red Hat Enterprise Linux

Red Hat Enterprise Linux (RHEL) versions 8 and 9 have received several security updates to address vulnerabilities in packages such as kernel, vim, webkit2gtk3, and compat-libtiff3. These updates aim to fix security issues rated as moderate or important, with some also addressing bugs and adding enhancements. RHEL versions 8 and 10, as well as Red Hat OpenShift Container Platform release 4.12.81, have all received security updates from Red Hat in recent releases. The updates cover various products including kernel, vim, Camel Quarkus, webkit2gtk3, and more, with some having a moderate or important security impact.

Rocky Linux

Multiple security updates are available for various packages on Rocky Linux 8, including Vim to address a moderate-level vulnerability. Additionally, kernel security updates have been released, affecting both the regular kernel and kernel-rt packages, with ratings as moderate. For Rocky Linux 10 and 9, several important security patches are available, impacting packages such as .NET, Firefox, LibSSH, and others. These updates aim to improve system security by addressing potential vulnerabilities and providing a detailed severity rating for each issue through the Common Vulnerability Scoring System (CVSS) base score.

Slackware Linux

Several updates are available for Slackware to fix security issues, including new packages for Mozilla Thunderbird and Firefox, Samba, libarchive and SQLite. These updates address various vulnerabilities such as uninitialized memory disclosure, command injection, out-of-boundary access, and memory corruption issues. Additionally, an update is also available for the stunnel package, which fixes a vulnerability that could lead to unintended configurations when using service-level multivalued options with global defaults. The details of these security fixes are available through links provided by the Slackware Linux Security Team.

SUSE Linux

SUSE Linux has released several security updates to address vulnerabilities in various software packages. These updates include fixes for the Linux kernel, as well as other packages such as Docker, Go, Podman, OpenSSL, HAProxy, libxslt, qt6-base, samba, squid, and more. The updates are available for different service packs of SLE 15, including SP3, SP4, and SP5. The security patches aim to secure network file sharing, authentication, and other critical functionalities in SUSE Linux systems.

Ubuntu Linux

Ubuntu has released updates to address security issues in various packages, including the Linux kernel and Apache Subversion. Multiple kernel updates were released to fix vulnerabilities affecting different versions of Ubuntu, including 20.04 LTS, 18.04 LTS, and 22.04 LTS for Oracle Cloud systems. Additionally, security notices were issued for other packages such as Samba, Redis, .NET, and MuPDF to address various vulnerabilities. These updates are available to ensure the security and stability of Ubuntu systems and derivatives.

Tuxrepair