USN-6338-2: Linux kernel vulnerabilities
Zi Fan Tan discovered that the binder IPC implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause...
USN-6339-2: Linux kernel vulnerabilities
It was discovered that the NTFS file system implementation in the Linux kernel did not properly validate MFT flags in certain situations. An attacker could...
USN-6340-2: Linux kernel vulnerabilities
Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did not properly perform permissions checks when handling HCI sockets. A physically proximate attacker...
Friday Squid Blogging: Glass Squid Video
Here’s a fantastic video of Taonius Borealis, a glass squid, from NOAA. As usual, you can also use this squid post to talk about the...
USN-6342-2: Linux kernel (Azure)
Tavis Ormandy discovered that some AMD processors did not properly handle speculative execution of certain vector register instructions. A local attacker could use this to...
APPLE-SA-2023-09-07-3 watchOS 9.6.2
Posted by Apple Product Security via Fulldisclosure on Sep 08 APPLE-SA-2023-09-07-3 watchOS 9.6.2 watchOS 9.6.2 addresses the following issues. Information about the security content is...
APPLE-SA-2023-09-07-2 iOS 16.6.1 and iPadOS 16.6.1
Posted by Apple Product Security via Fulldisclosure on Sep 08 APPLE-SA-2023-09-07-2 iOS 16.6.1 and iPadOS 16.6.1 iOS 16.6.1 and iPadOS 16.6.1 addresses the following issues....
APPLE-SA-2023-09-07-1 macOS Ventura 13.5.2
Posted by Apple Product Security via Fulldisclosure on Sep 08 APPLE-SA-2023-09-07-1 macOS Ventura 13.5.2 macOS Ventura 13.5.2 addresses the following issues. Information about the security...
Congratulations, You’re Compliant: Charting Your Path Ahead
What comes next after you've achieved compliance? We've got seven things for your consideration. A CIS SecureSuite Membership can help. Read More
golang-1.21.1-1.fc39
FEDORA-2023-4c35736385 Packages in this update: golang-1.21.1-1.fc39 Update description: This release includes fixes to the go command, the crypto/tls, net/http packages, and several more. Read More