Linux

Oracle Linux 9 — librabbitmq — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 9

Oracle Linux 9 — librabbitmq — vulnerability — patch and remediation guide (ELSA-2023-6482)

🟡 Medium   ⏱ 10–30 min  Last verified: 30 April 2024 Affected versions: Oracle Linux 9 📖 ~4 min read  •  Source: ELSA advisory ELSA-2023-6482 Related CVEs: CVE-2023-35789 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
SLES 12 — gimp — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gimp — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:0746 (see also SUSE bugzilla) Related CVEs: CVE-2023-44442 CVE-2023-44444 CVE-2022-32990 CVE-2022-30067 CVE-2017-17784 CVE-2017-17785 CVE-2017-17786 CVE-2017-17787  +11 more Upstream summary: GIMP PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability […]

Read more
Alpine Linux 3.18 — openjdk11 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux 3.18

Alpine Linux 3.18 — openjdk11 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.18 / fixed in 11.0.9_p11-r0 📖 ~4 min read  •  Source: Alpine secdb entry — openjdk11 11.0.9_p11-r0 Related CVEs: CVE-2020-14779 CVE-2020-14781 CVE-2020-14782 CVE-2020-14792 CVE-2020-14796 CVE-2020-14797 CVE-2020-14798 CVE-2020-14803  +12 more Upstream summary: Alpine community repository for vv3.18 ships openjdk11 11.0.9_p11-r0 which […]

Read more
SLES 12 — libraw9 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libraw9 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 30 April 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2300-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8367 CVE-2020-22628 CVE-2023-1729 CVE-2021-32142 CVE-2017-6889 CVE-2020-15503 CVE-2013-2126 CVE-2013-2127  +12 more Upstream summary: The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors […]

Read more
Debian 12 — shadowsocks-libev — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — shadowsocks-libev — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-15924 CVE-2019-5152 CVE-2019-5163 CVE-2019-5164 Upstream summary: In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via […]

Read more
AlmaLinux 8 — bubblewrap — vulnerability — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — bubblewrap — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2024:6422 Related CVEs: CVE-2024-42472 Upstream summary: Bubblewrap (/usr/bin/bwrap) is a core execution engine for unprivileged containers that works as a setuid binary on kernels without user namespaces. Security Fix(es): * flatpak: Access […]

Read more
Amazon Linux 2 — gstreamer-plugins-bad-free — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — gstreamer-plugins-bad-free — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2025-2972 Related CVEs: CVE-2023-40474 Upstream summary: Integer overflow leading to heap overwrite in MXF file handling with uncompressed video NOTE: https://gstreamer.freedesktop.org/security/sa-2023-0006.html NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/5362 NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/ce17e968e4cf900d28ca5b46f6e095febc42b4f0 (CVE-2023-40474) Table of […]

Read more
Debian 12 — diffoscope — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — diffoscope — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-0359 CVE-2024-25711 Upstream summary: diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive. Table of contents Symptom & Impact Environment […]

Read more
openSUSE Tumbleweed — xmlgraphics-fop — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — xmlgraphics-fop — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:4054-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-28168 Upstream summary: Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. […]

Read more
Debian 12 — libnl3 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libnl3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2017-0553 Upstream summary: An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This […]

Read more
CHAT