Category Archives: Advisories

emacs-29.3-2.fc40

Read Time:10 Second

FEDORA-2024-7985b5f326

Packages in this update:

emacs-29.3-2.fc40

Update description:

Obsolete the newer emacs-nox now in F39, fixing system upgrades

New upstream release 29.3, fixes rhbz#2271287

Read More

chromium-123.0.6312.105-1.fc39

Read Time:15 Second

FEDORA-2024-39b249a59c

Packages in this update:

chromium-123.0.6312.105-1.fc39

Update description:

update to 123.0.6312.105

* High CVE-2024-3156: Inappropriate implementation in V8
* High CVE-2024-3158: Use after free in Bookmarks
* High CVE-2024-3159: Out of bounds memory access in V8

Read More

chromium-123.0.6312.105-1.fc38

Read Time:15 Second

FEDORA-2024-5e32ce95a3

Packages in this update:

chromium-123.0.6312.105-1.fc38

Update description:

update to 123.0.6312.105

* High CVE-2024-3156: Inappropriate implementation in V8
* High CVE-2024-3158: Use after free in Bookmarks
* High CVE-2024-3159: Out of bounds memory access in V8

Read More

LSN-0102-1: Kernel Live Patch Security Notice

Read Time:1 Minute, 22 Second

It was discovered that a race condition existed in the io_uring subsystem
in the Linux kernel, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code.(CVE-2023-1872)

Lonial Con discovered that the netfilter subsystem in the Linux kernel
contained a memory leak when handling certain element flush operations. A
local attacker could use this to expose sensitive information (kernel
memory).(CVE-2023-4569)

It was discovered that the TLS subsystem in the Linux kernel did not
properly perform cryptographic operations in some situations, leading to a
null pointer dereference vulnerability. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code.(CVE-2023-6176)

It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code.(CVE-2023-51781)

Jann Horn discovered that the TLS subsystem in the Linux kernel did not
properly handle spliced messages, leading to an out-of-bounds write
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code.(CVE-2024-0646)

Notselwyn discovered that the netfilter subsystem in the Linux kernel did
not properly handle verdict parameters in certain cases, leading to a use-
after-free vulnerability. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.(CVE-2024-1086)

Read More