FEDORA-2024-0912cd3ad9
Packages in this update:
incus-6.8-1.fc41
Update description:
Update to 6.8 to get various features and fixes
incus-6.8-1.fc41
Update to 6.8 to get various features and fixes
It was discovered that YARA did not properly sanitize its
configuration settings. An attacker could potentially exploit this issue to
cause a denial of service.
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
– Ext4 file system;
– Network traffic control;
– VMware vSockets driver;
(CVE-2024-49967, CVE-2024-53057, CVE-2024-50264)
age-1.2.1-1.fc41
Update to 1.2.1 to fix https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c security issue.
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code. Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 16.04 LTS were previously addressed in USN-6403-1,
USN-6403-2, and USN-6403-3. This update addresses the issue in Ubuntu 14.04
LTS.
A CISA Directive sets out actions all US federal agencies must take to identify and secure cloud tenants in their environments
SlashNext reports a 202% increase in overall phishing messages and a 703% surge in credential-based phishing attacks in 2024
Malicious campaigns targeting VSCode extensions have recently expanding to npm, risking software supply chains
Online romance and investment scams are painful enough without its victims being described as “pigs.”
Read more in my article on the Hot for Security blog.