Category Archives: Advisories

grub2-2.06-118.fc38

Read Time:24 Second

FEDORA-2024-01f402fae5

Packages in this update:

grub2-2.06-118.fc38

Update description:

Security fix for CVE-2023-4692

Security fix for CVE-2023-4693

Fri Mar 08 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-118

fs/xfs: Handle non-continuous data blocks in directory extents
Related: #2254370

Fri Mar 08 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-117

GRUB2 NTFS driver vulnerabilities
(CVE-2023-4692)
(CVE-2023-4693)
Resolves: #2236613
Resolves: #2241978
Resolves: #2241976
Resolves: #2238343

Read More

grub2-2.06-120.fc39

Read Time:24 Second

FEDORA-2024-d09797f550

Packages in this update:

grub2-2.06-120.fc39

Update description:

Security fix for CVE-2023-4692

Security fix for CVE-2023-4693

Fri Apr 12 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-120

fs/xfs: Handle non-continuous data blocks in directory extents
Related: #2254370

Fri Mar 08 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-119

GRUB2 NTFS driver vulnerabilities
(CVE-2023-4692)
(CVE-2023-4693)
Resolves: #2236613
Resolves: #2241978
Resolves: #2241976
Resolves: #2238343

Read More

grub2-2.06-121.fc40

Read Time:24 Second

FEDORA-2024-2b545d3085

Packages in this update:

grub2-2.06-121.fc40

Update description:

Security fix for CVE-2023-4692

Security fix for CVE-2023-4693

Fri Apr 12 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-121

fs/xfs: Handle non-continuous data blocks in directory extents
Related: #2254370

Fri Mar 08 2024 Nicolas Frayer nfrayer@redhat.com – 2.06-120

GRUB2 NTFS driver vulnerabilities
(CVE-2023-4692)
(CVE-2023-4693)
Resolves: #2236613
Resolves: #2241978
Resolves: #2241976
Resolves: #2238343

Read More

freerdp-3.5.0-1.fc40

Read Time:12 Second

FEDORA-2024-050266dc33

Packages in this update:

freerdp-3.5.0-1.fc40

Update description:

Update to 3.5.0 (CVE-2024-32039, CVE-2024-32040, CVE-2024-32041, CVE-2024-32458, CVE-2024-32459, CVE-2024-32460)

Read More

DSA-5665-1 tomcat10 – security update

Read Time:42 Second

Several security vulnerabilities have been discovered in the Tomcat
servlet and JSP engine.

CVE-2023-46589

Tomcat 10 did not correctly parse HTTP trailer headers. A trailer header
that exceeded the header size limit could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request
smuggling when behind a reverse proxy.

CVE-2024-24549

Denial of Service due to improper input validation vulnerability for
HTTP/2. When processing an HTTP/2 request, if the request exceeded any of
the configured limits for headers, the associated HTTP/2 stream was not
reset until after all of the headers had been processed.

CVE-2024-23672

Denial of Service via incomplete cleanup vulnerability. It was possible
for WebSocket clients to keep WebSocket connections open leading to
increased resource consumption.

https://security-tracker.debian.org/tracker/DSA-5665-1

Read More

kubernetes-1.29.4-1.fc40

Read Time:18 Second

FEDORA-2024-ce2eefc399

Packages in this update:

kubernetes-1.29.4-1.fc40

Update description:

Update Kubernetes to v1.29.4 for Fedora 40. Resolves CVE-2024-3177: Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin.

Additional bug and regression fixes include a bump to Golang.org/x/net to v0.23.0 to address CVE-2023-45288 .

Read More