Linux

Debian 12 — erlang — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — erlang — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-0130 CVE-2011-0766 CVE-2011-3389 CVE-2014-1693 CVE-2014-3566 CVE-2015-2774 CVE-2016-1000107 CVE-2016-10253  +12 more Upstream summary: lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which […]

Read more
Debian 12 — loguru — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — loguru — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-0338 Upstream summary: Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
Debian 12 — open-iscsi — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — open-iscsi — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-3099 CVE-2007-3100 CVE-2009-1297 CVE-2017-17840 CVE-2020-13987 CVE-2020-13988 CVE-2020-17437 Upstream summary: usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of […]

Read more
Debian 12 — libapache-mod-jk — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — libapache-mod-jk — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2007-0774 CVE-2007-1860 CVE-2008-5519 CVE-2014-8111 CVE-2018-11759 CVE-2023-41081 CVE-2024-46544 Upstream summary: Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.157-139.675 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.157-139.675 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2023-117 Related CVEs: CVE-2023-1078 CVE-2023-26545 CVE-2023-0179 CVE-2022-3623 CVE-2022-4378 Upstream summary: The upstream bug report describes this issue as follows: A flaw found in the Linux Kernel in RDS (Reliable Datagram […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.162-141.675 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.162-141.675 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2023-121 Related CVEs: CVE-2023-1077 CVE-2023-28466 CVE-2023-1078 CVE-2023-26545 CVE-2023-0179 Upstream summary: kernel: Type confusion in pick_next_rt_entity(), which can result in memory corruption. (CVE-2023-1077) do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through […]

Read more
Debian 12 — xsok — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — xsok — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2003-0949 Upstream summary: xsok 1.02 does not properly drop privileges before finding and executing the "gunzip" program, which allows local users to execute arbitrary commands. Table of contents […]

Read more
Debian 12 — gpp — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — gpp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 April 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-17076 Upstream summary: GPP through 2.25 will try to use more memory space than is available on the stack, leading to a segmentation fault or possibly unspecified other […]

Read more
Ubuntu 22.04 — netatalk — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — netatalk — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2024 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7347-1 Related CVEs: CVE-2024-38439 CVE-2024-38440 CVE-2024-38441 CVE-2022-22995 CVE-2023-42464 CVE-2021-31439 CVE-2022-0194 CVE-2022-23121  +6 more Upstream summary: It was discovered that Netatalk did not properly manage memory under certain circumstances. A remote […]

Read more
Alpine Linux 3.19 — graphicsmagick — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux 3.19

Alpine Linux 3.19 — graphicsmagick — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.19 / fixed in 1.3.38-r0 📖 ~4 min read  •  Source: Alpine secdb entry — graphicsmagick 1.3.38-r0 Related CVEs: CVE-2022-1270 CVE-2020-12672 CVE-2020-10938 CVE-2018-18544 CVE-2018-20189 CVE-2019-7397 CVE-2019-11473 CVE-2019-11474  +12 more Upstream summary: Alpine community repository for vv3.19 ships graphicsmagick 1.3.38-r0 which […]

Read more
CHAT