Security 10908 Published by

Several major Linux distributions have released security updates over the past week to fix various vulnerabilities across their packages. The affected distributions include AlmaLinux, Debian GNU/Linux, Fedora Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux, with multiple packages receiving patches to address issues such as remote code execution, denial of service, and information disclosure. These updates aim to protect users from potential threats by addressing known vulnerabilities in the affected software, with some updates also including bug fixes and enhancements to packages and images.





AlmaLinux

AlmaLinux has released several security updates to fix various vulnerabilities across its packages. The updates include fixes for sssd, tigervnc, pcs, OpenSSL, libssh, and other applications, addressing both moderate and important-level issues. Additionally, separate updates have been issued for AlmaLinux 9, including a security patch for systemd to address a moderate-level vulnerability. Multiple packages such as go-toolset, GIMP, Firefox, kernel-rt, and others also received patches as part of the updates.

Debian GNU/Linux

Debian has released multiple security updates to address various vulnerabilities in its packages, including gnome-shell-extension-gsconnect and pytorch. Additionally, updates have been released for other packages such as cups-filters, unbound, mako, xen, containerd, mod-auth-openidc, webkit2gtk, openvpn, libhtp, chromium, and krita. These updates aim to fix issues that could lead to denial of service, information disclosure, or arbitrary code execution on Debian systems. The updates are available for various Debian distributions, including Buster, Bookworm, Trixie, and Debian GNU/Linux 11 LTS.

Fedora Linux

Fedora has released security updates to address vulnerabilities in various packages across its 41, 42, and 43 versions. The updates target issues such as remote code execution and LDAP injection, improving overall system security. Multiple packages have been updated, including gnutls, webkitgtk, unbound, python, pgAdmin, libcoap, timg, fcgi, and chromium. These updates are now available for download, with specific information provided for each affected package and version.

Oracle Linux

Oracle has released several security updates and bug fixes for its Linux distributions, including Oracle Linux 10 and 8. These updates address various vulnerabilities in packages such as Thunderbird, Firefox, Java, kernel, and others. The company also made updates available for version 10 of Oracle Linux, which include patches for multiple packages to address vulnerabilities. These security updates are intended to protect users from potential threats by addressing known vulnerabilities in the affected software.

Red Hat Enterprise Linux

Red Hat has released various security updates for its products, including kernel, libxml2, Firefox, and other packages, affecting different versions of Red Hat Enterprise Linux (RHEL). The updates address vulnerabilities with a security impact ranging from moderate to important, making it essential for users to install them. In addition to these updates, several other RHEL products have received security patches, such as GIMP, Expat, systemd, and xorg-x11-server, among others. Some of the updates also include bug fixes, enhancements to packages and images, and important security updates for specific Red Hat products like OpenShift Container Platform 4.13.62.

Rocky Linux

Rocky Linux users need to install several security updates to protect their systems. These updates include fixes for container-related modules and tools, as well as critical vulnerabilities in Firefox that require attention. Other packages receiving security updates include Shadow-Utils, Qt6-Qtsvg, LibXML2, NodeJS, Kernel, Go-Toolset, and Virt, with some updates having moderate severity ratings. Rocky Linux users can access these updates through the provided links to learn more about the specific vulnerabilities being addressed.

Slackware Linux

Security updates are available for two packages on Slackware: libpng and httpd. The libpng update fixes a high-severity issue related to an out-of-bounds read, which could potentially be exploited. Meanwhile, the httpd update addresses multiple security issues that could allow bypasses or data leaks. Users of Slackware 15.0 and -current should take advantage of these updates to ensure their system remains secure.

SUSE Linux

Several security updates have been released for various Linux distributions, including SUSE. The updates cover a range of packages, such as Java and OpenSSH, Python libraries like cbor2, and applications like Chromium and Git-Bug. The openSUSE project has also released multiple security updates to address vulnerabilities in its packages. These updates are available for different versions of openSUSE Leap and Tumbleweed and can be installed to ensure the security and stability of SUSE Linux systems.

Ubuntu Linux

Ubuntu Linux has released several security updates to address vulnerabilities in various software packages, including GNU binutils and CRaC JDK versions. Additionally, updates have been made to packages such as Unbound, Django, PostgreSQL, KDE Connect, Ghostscript, Linux kernel, CUPS, and MAME to fix security issues. These updates aim to protect Ubuntu systems and their derivatives from potential domain hijack attacks and other vulnerabilities. The security fixes include patches for FIPS-compliant versions of the Linux kernel used by Google Cloud, Microsoft Azure, and generic FIPS configurations.

Tuxrepair