Security 10922 Published by

Several major Linux distributions have released security updates in recent weeks to address various vulnerabilities. These updates include fixes for issues such as resource exhaustion, denial of service, information disclosure, and arbitrary code execution across multiple packages on AlmaLinux, Debian GNU/Linux, Fedora Linux, Gentoo Linux, Oracle Linux, Red Hat Enterprise Linux, Rocky Linux, Slackware Linux, SUSE Linux, and Ubuntu Linux. The updates aim to improve the overall security posture of these systems by addressing vulnerabilities in packages such as Java, Go Toolset, GIMP, Python, PHP, kernel, OpenSSL, curl, and more. Users are advised to apply these patches promptly to ensure their systems remain safe and stable.





AlmaLinux

Several important security updates have been released for AlmaLinux, including fixes for vulnerabilities in Java 21 OpenJDK, Go Toolset, GIMP, net-snmp, kernel, and Python urllib3. These updates address various issues such as resource exhaustion, denial of service, and information disclosure. The AlmaLinux Security team has also issued security patches for python3-urllib3, openjdk, openssl, and other packages to protect against arbitrary code execution and remote code vulnerabilities. Additionally, updates have been released for Python, PHP, kernel, openjdk, and curl on AlmaLinux 9 to address potential system stability issues.

Debian GNU/Linux

Multiple security vulnerabilities have been addressed in various Debian packages, including inetutils, openjdk-17, taglib, zvbi, Apache, ImageMagick, OpenSSL, Python-Django, DCMTK, and more. The updates fix issues such as authentication bypass problems, incorrect certificate validation, integer overflows, heap buffer overflows, and header injection. Security updates have been released for Debian GNU/Linux, addressing vulnerabilities in Chromium, Ceph, Libsodium, Pillow, and other packages. These updates aim to prevent denial-of-service attacks, arbitrary code execution, information leaks, and other potential security risks associated with these vulnerabilities.

Fedora Linux

Security updates have been released for various packages on Fedora 42 and 43, including MinGW, Ghostscript, Glibc, Bind, CURL, Chromium, FreeRDP, Python-TinyCSS2, HarfBuzz-Shaper, Weasyprint, OpenJDK, NodeJS, and OpenSSL. These updates address vulnerabilities in multiple libraries, including mingw-libsoup, harfbuzz, glib2, and others. Fedora 42 has received more security updates than Fedora 43, with five updates so far for the former version. The updates aim to fix various security issues, including several CVEs, to ensure the stability and security of Fedora Linux systems.

Gentoo Linux

Gentoo Linux has released several security updates to address various vulnerabilities. The updates include patches for Commons-BeanUtils and Asterisk, which can lead to arbitrary code execution and multiple issues respectively. Additionally, the updates cover GIMP, Vim, and Inetutils, potentially fixing security problems in these applications. These updates aim to improve the overall security of Gentoo Linux systems.

Oracle Linux

Multiple updates are available for Oracle Linux to improve security and fix bugs. These updates affect various versions of Oracle Linux, including 7, 8, 9, and 10. Specific components such as Python, GCC-Toolset, and the kernel have received targeted updates.

Red Hat Enterprise Linux

Red Hat Enterprise Linux (RHEL) has released multiple security updates for various versions, including 7, 8, and 9. The updates cover numerous packages such as PHP, Poppler, kernel, resource-agents, fence-agents, glibc, glib2, curl, openssl, Python, GIMP, Spice Client, and more. These updates have been rated with a Moderate or Important security impact and address vulnerabilities in the affected components.

Rocky Linux

Rocky Linux has received several security updates to address potential vulnerabilities. The updates affect various packages such as Java-1.8.0-OpenJDK, PHP 8.3, Python 3.11 and 3.12, Grafana, glibc, OpenSSL, curl, gcc-toolset-15-binutils, spice-client-win, grafana-pcp, and GIMP. These updates are available for different versions of Rocky Linux, including 8 and 9, and aim to improve the security posture of the system.

Slackware Linux

Mozilla Thunderbird has been updated on Slackware to address security issues, with the latest version being 140.7. This update affects both Slackware 15.0 and -current. Additionally, Expat packages have also been updated for Slackware to fix vulnerabilities that could cause denial of service or integer overflow in these same versions. The updates aim to improve overall security on these platforms.

SUSE Linux

SUSE Linux has received numerous security updates to address various vulnerabilities. The affected packages include CoreDNS, Python-urllib3, Chromium, Go 1.25 with OpenSSL, PHP, Xen, Kernel-Firmware, and many others across multiple updates. Some of these updates are rated as critical or important, emphasizing the need for users to apply them promptly. These security patches aim to improve overall safety and stability on SUSE Linux systems.

Ubuntu Linux

Ubuntu has received several security updates to address various vulnerabilities. The affected packages include GNU Screen, Form-Data, Git LFS, cJSON, jaraco.context, OpenSSL, FFmpeg, TeX Live, containerd, the Linux kernel, and wlc. These updates aim to fix issues such as denial of service, exposing sensitive information, out-of-bounds memory access, file overwriting, and multiple security vulnerabilities within the Linux kernel. Users are advised to apply these patches promptly to ensure their Ubuntu systems remain safe and stable.

Tuxrepair