Linux

Debian 12 — jruby — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — jruby — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2010-1330 CVE-2011-4838 CVE-2012-5370 CVE-2015-3900 CVE-2017-17742 CVE-2018-1000073 CVE-2018-1000074 CVE-2018-1000075  +12 more Upstream summary: The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not […]

Read more
Debian 12 — scheme48 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — scheme48 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2014-4150 Upstream summary: The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp. Table of contents […]

Read more
Debian 11 — gss-ntlmssp — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — gss-ntlmssp — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 August 2023 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2023-25563 CVE-2023-25565 CVE-2023-25567 Upstream summary: GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, multiple out-of-bounds reads when decoding NTLM […]

Read more
Debian 12 — quota — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — quota — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-3417 Upstream summary: The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which […]

Read more
Debian 12 — lm-sensors — vulnerability — patch and remediation guide — diagnosis and fix on Debian 12

Debian 12 — lm-sensors — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 August 2023 Affected versions: Debian 12 (bookworm) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2005-2672 Upstream summary: pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary […]

Read more
Ubuntu 16.04 — libxpm — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — libxpm — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 August 2023 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6408-2 Related CVEs: CVE-2023-43786 CVE-2023-43787 CVE-2023-43788 CVE-2023-43789 CVE-2022-44617 CVE-2022-46285 CVE-2022-4883 CVE-2016-10164 Upstream summary: USN-6408-1 fixed several vulnerabilities in libXpm. This update provides the corresponding update for Ubuntu 14.04 LTS, Ubuntu […]

Read more
Common Problems 120022

Debian 12 – initramfs generation fails with unpacking or compression errors

🟠 High   ⏱ 5–30 min  Last verified: 30 August 2023 Affected versions: Debian 12 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & […]

Read more
Ubuntu 20.04 — harfbuzz — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — harfbuzz — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 August 2023 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7251-1 Related CVEs: CVE-2023-25193 CVE-2022-33068 Upstream summary: It was discovered that HarfBuzz incorrectly handled shaping certain fonts. A remote attacker could possibly use this issue to cause HarfBuzz to consume […]

Read more
Ubuntu 22.04 — gnome-control-center — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 22.04

Ubuntu 22.04 — gnome-control-center — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 August 2023 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6554-1 Related CVEs: CVE-2023-5616 CVE-2022-1736 Upstream summary: Zygmunt Krynicki discovered that GNOME Settings did not accurately reflect the SSH remote login status when the system was configured to use systemd […]

Read more
Oracle Linux 8 — kubernetes — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — kubernetes — vulnerability — patch and remediation guide (ELSA-2023-12561)

🟠 High   ⏱ 15–60 min  Last verified: 30 August 2023 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2023-12561 Related CVEs: CVE-2023-2728 CVE-2023-2727 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
CHAT