FEDORA-2024-0078a55acf
Packages in this update:
mosquitto-2.0.19-1.fc41
Update description:
Update to 2.0.19
Fix FTBFS (closes rhbz#2300978)
mosquitto-2.0.19-1.fc41
Update to 2.0.19
Fix FTBFS (closes rhbz#2300978)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
– GPU drivers;
– BTRFS file system;
– F2FS file system;
– GFS2 file system;
– BPF subsystem;
– Netfilter;
– RxRPC session sockets;
– Integrity Measurement Architecture(IMA) framework;
(CVE-2024-41009, CVE-2024-26677, CVE-2024-42160, CVE-2024-39494,
CVE-2024-39496, CVE-2024-38570, CVE-2024-27012, CVE-2024-42228)
redis-7.2.6-1.fc39
Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT
Upgrade urgency SECURITY: See security fixes below.
Security fixes
CVE-2024-31449 Lua library commands may lead to stack overflow and potential RCE.
CVE-2024-31227 Potential Denial-of-service due to malformed ACL selectors.
CVE-2024-31228 Potential Denial-of-service due to unbounded pattern matching.
redis-7.2.6-1.fc40
Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT
Upgrade urgency SECURITY: See security fixes below.
Security fixes
CVE-2024-31449 Lua library commands may lead to stack overflow and potential RCE.
CVE-2024-31227 Potential Denial-of-service due to malformed ACL selectors.
CVE-2024-31228 Potential Denial-of-service due to unbounded pattern matching.
It was discovered that GNOME Shell mishandled extensions that fail to
reload, possibly leading to extensions staying enabled on the lock screen.
An attacker could possibly use this issue to launch applications, view
sensitive information, or execute arbitrary commands. (CVE-2017-8288)
It was discovered that the GNOME Shell incorrectly handled certain
keyboard inputs. An attacker could possibly use this issue to invoke
keyboard shortcuts, and potentially other actions while the workstation
was locked. (CVE-2019-3820)
A CVSS score 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N severity vulnerability discovered by ‘Poh Jia Hao of STAR Labs SG Pte. Ltd.’ was reported to the affected vendor on: 2024-10-03, 0 days ago. The vendor is given until 2025-01-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.
Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.
firefox-131.0-2.fc41
New upstream builds (131.0)
firefox-131.0-2.fc40
New upstream builds (131.0)