Linux

Ubuntu 20.04 — gegl — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — gegl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 April 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5251-1 Related CVEs: CVE-2021-45463 Upstream summary: It was discovered that GEGL incorrectly filtered and escaped file path input data when using the C system() function for execution of the ImageMagick […]

Read more
How to Install Portainer on Debian 11 — step-by-step Debian 11 tutorial on Progressive Robot

How to Install Portainer on Debian 11

Introduction This guide explains how to Install Portainer on Debian 11 on Debian 11 Bullseye. Debian Bullseye uses systemd for service management, nftables as the underlying packet filter (with ufw or iptables front-ends still available), and AppArmor for mandatory access control. Every command is designed for a minimal Debian 11 install with the standard repositories […]

Read more
SLES 15 — xom — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — xom — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 April 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:712-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-33813 Upstream summary: An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. […]

Read more
SLES 15 — libtcmu2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libtcmu2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 April 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:69-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-3139 Upstream summary: In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to […]

Read more
Amazon Linux 2 — apr-util — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — apr-util — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-1937 Related CVEs: CVE-2022-25147 Upstream summary: 2023-05-23: The severity level was changed from Critical to Medium. Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) […]

Read more
Debian 11 — golang-1.15 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — golang-1.15 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 April 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-15586 CVE-2020-16845 CVE-2020-24553 CVE-2020-28362 CVE-2020-28366 CVE-2020-28367 CVE-2020-29509 CVE-2020-29510  +12 more Upstream summary: Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as […]

Read more
How to Configure BGP Routing with BIRD on RHEL 8 — step-by-step RHEL 8 tutorial on Progressive Robot

How to Configure BGP Routing with BIRD on RHEL 8

Border Gateway Protocol (BGP) is the routing protocol that powers the internet, exchanging routing information between autonomous systems (AS). On RHEL 8, the BIRD Internet Routing Daemon provides a lightweight, production-grade BGP implementation available through the EPEL repository. This tutorial walks through installing BIRD, writing a BGP configuration with neighbor relationships and route filters, verifying […]

Read more
Oracle Linux 8 — virt:ol and virt-devel:rhel security, bug fix, and — enhancement update — new behaviour and fixes — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — virt:ol and virt-devel:rhel security, bug fix, and — enhancement update — new behaviour and fixes (ELSA-2020-4676)

🟡 Medium   ⏱ 10–30 min  Last verified: 18 April 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2020-4676 Related CVEs: CVE-2019-15890 CVE-2019-20485 CVE-2020-10703 CVE-2020-14301 CVE-2020-14339 CVE-2020-1983 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
How to Set Up Puppet Agent on CentOS Stream 9 — step-by-step CentOS Stream 9 tutorial on Progressive Robot

How to Set Up Puppet Agent on CentOS Stream 9

Introduction How to Set Up Puppet Agent on CentOS Stream 9 on CentOS Stream 9 provides administrators with a robust, enterprise-ready workflow that integrates cleanly with systemd, SELinux, firewalld, and the modern AppStream module system. In this tutorial we will walk through every step required, from package installation to verification, so that the resulting configuration […]

Read more
CHAT