Linux

Oracle Linux 8 — grub2 — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — grub2 — vulnerability — patch and remediation guide (ELSA-2022-9595)

🟠 High   ⏱ 15–60 min  Last verified: 28 August 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-9595 Related CVEs: CVE-2021-3696 CVE-2022-28737 CVE-2022-28734 CVE-2022-28735 CVE-2022-28736 CVE-2021-3697 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
How To Set Up an Endlessh Tarpit on Ubuntu 22.04 — step-by-step Linux tutorial on Progressive Robot

How To Set Up an Endlessh Tarpit on Ubuntu 22.04

When looking at authentication logs, you might see several failed login attempts from various IP addresses that often .come from a node on a botnet. While you may not be able to stop these attacks, you can slow them down with tarpits. In this tutorial, you will install and configure Endlessh, a tarpit that slowly sends an infinitely long banner to any user attempting login, as well as configure the SSH service to run on a different port.

Read more
Debian 11 — kubernetes — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — kubernetes — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 August 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2016-7075 CVE-2017-1000056 CVE-2017-1002101 CVE-2017-1002102 CVE-2018-1002100 CVE-2018-1002102 CVE-2018-1002105 CVE-2019-1002100  +12 more Upstream summary: It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 […]

Read more
How to Configure Network QoS with tc on RHEL 9 — step-by-step RHEL 9 tutorial on Progressive Robot

How to Configure Network QoS with tc on RHEL 9

Network Quality of Service (QoS) lets you control how bandwidth is distributed across different types of traffic, ensuring that latency-sensitive applications like VoIP or interactive SSH sessions remain responsive even when bulk transfers saturate the link. The Linux tc (traffic control) subsystem implements this through a combination of queuing disciplines, classes, and packet filters. This […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.102-99.473 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.102-99.473 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2022-077 Related CVEs: CVE-2022-1786 Upstream summary: io_uring: always use original task when preparing req identity (CVE-2022-1786) Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
Debian 11 — tcpdump — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — tcpdump — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 August 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-0380 CVE-2002-1350 CVE-2003-0093 CVE-2003-0108 CVE-2003-0145 CVE-2003-0989 CVE-2003-1029 CVE-2004-0055  +12 more Upstream summary: Buffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service […]

Read more
How to Set Up Dovecot IMAP Server on Debian 11 — step-by-step Debian 11 tutorial on Progressive Robot

How to Set Up Dovecot IMAP Server on Debian 11

Introduction Deploying set up dovecot imap server on debian 11 on a Debian 11 Bullseye machine is straightforward thanks to Debian’s policy-compliant packaging. Unlike rpm-based distributions, Debian stores configuration helpers in /etc/default/, uses update-rc.d for older init scripts, and provides dpkg-reconfigure for interactive package configuration. This tutorial stays on the systemd path throughout. Prerequisites Before […]

Read more
AlmaLinux 9 — bash — vulnerability — patch and remediation guide — diagnosis and fix on AlmaLinux 9

AlmaLinux 9 — bash — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 9 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2023:0340 Related CVEs: CVE-2022-3715 Upstream summary: The bash packages provide Bash (Bourne-again shell), which is the default shell for AlmaLinux. Security Fix(es): * bash: a heap-buffer-overflow in valid_parameter_transform (CVE-2022-3715) For more details […]

Read more
Oracle Linux 8 — nodejs:18 security, bug fix, and — enhancement update — new behaviour and fixes — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — nodejs:18 security, bug fix, and — enhancement update — new behaviour and fixes (ELSA-2023-1583)

🟡 Medium   ⏱ 10–30 min  Last verified: 27 August 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2023-1583 Related CVEs: CVE-2023-23920 CVE-2023-23936 CVE-2023-24807 CVE-2022-25881 CVE-2021-35065 CVE-2023-23918 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
CHAT