Category Archives: Advisories

USN-6123-1: Linux kernel (OEM) vulnerabilities

Read Time:1 Minute, 9 Second

Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in
the netfilter subsystem of the Linux kernel when processing batch requests,
leading to a use-after-free vulnerability. A local attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2023-32233)

Reima Ishii discovered that the nested KVM implementation for Intel x86
processors in the Linux kernel did not properly validate control registers
in certain situations. An attacker in a guest VM could use this to cause a
denial of service (guest crash). (CVE-2023-30456)

It was discovered that the Xircom PCMCIA network device driver in the Linux
kernel did not properly handle device removal events. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2023-1670)

Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu
Linux kernel contained a race condition when handling inode locking in some
situations. A local attacker could use this to cause a denial of service
(kernel deadlock). (CVE-2023-2612)

It was discovered that the NTFS file system implementation in the Linux
kernel did not properly handle a loop termination condition, leading to an
out-of-bounds read vulnerability. A local attacker could use this to cause
a denial of service (system crash) or possibly expose sensitive
information. (CVE-2023-26606)

Read More

USN-6122-1: Linux kernel (OEM) vulnerabilities

Read Time:28 Second

Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in
the netfilter subsystem of the Linux kernel when processing batch requests,
leading to a use-after-free vulnerability. A local attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2023-32233)

Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu
Linux kernel contained a race condition when handling inode locking in some
situations. A local attacker could use this to cause a denial of service
(kernel deadlock). (CVE-2023-2612)

Read More

USN-6121-1: Nanopb vulnerabilities

Read Time:18 Second

It was discovered that Nanopb incorrectly handled certain decode messages.
An attacker could possibly use this cause a denial of service or expose
sensitive information. (CVE-2020-26243)

It was discovered that Nanopb incorrectly handled certain decode messages.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2021-21401)

Read More

pypy-7.3.11-3.fc39

Read Time:15 Second

FEDORA-2023-4f1864b5cb

Packages in this update:

pypy-7.3.11-3.fc39

Update description:

Automatic update for pypy-7.3.11-3.fc39.

Changelog

* Mon May 29 2023 Charalampos Stratakis <cstratak@redhat.com> – 7.3.11-3
– Security fix for CVE-2023-24329
Resolves: rhbz#2174018

Read More