Linux

Amazon Linux 2 — gd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — gd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2023-2044 Related CVEs: CVE-2021-40145 CVE-2016-5766 Upstream summary: ** DISPUTED ** gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position […]

Read more
openSUSE Tumbleweed — libmysofa1 — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libmysofa1 — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2021-3756 CVE-2019-10672 CVE-2019-16092 CVE-2019-16093 CVE-2019-16091 CVE-2019-16094 CVE-2019-16095 CVE-2019-20063  +7 more Upstream summary: libmysofa is vulnerable to Heap-based Buffer Overflow Table of contents Symptom & Impact […]

Read more
Ubuntu 18.04 — svgpp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 18.04

Ubuntu 18.04 — svgpp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 October 2021 Affected versions: Ubuntu 18.04 (bionic) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6178-1 Related CVEs: CVE-2019-6246 CVE-2021-44960 Upstream summary: It was discovered that in SVG++ library that the demo application incorrectly managed memory resulting in a memory access violation under certain circumstances. […]

Read more
Oracle Linux 8 — libarchive — security and stability fixes — required update — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — libarchive — security and stability fixes — required update (ELSA-2019-3698)

🟡 Medium   ⏱ 10–30 min  Last verified: 18 October 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2019-3698 Related CVEs: CVE-2017-14503 CVE-2019-1000020 CVE-2019-1000019 CVE-2018-1000877 CVE-2018-1000878 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative […]

Read more
AlmaLinux 8 — apiguardian — vulnerability — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — apiguardian — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALBA-2020:5097 Upstream summary: Eclipse is an integrated development environment (IDE). The metadata for the eclipse:rhel8 module has been updated to remove the following unused profiles: c everything To check whether you have […]

Read more
Debian 11 — as31 — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — as31 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2012-0808 Upstream summary: as31 2.3.1-4 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or […]

Read more
Common Problems 117905

Ubuntu 18.04 LTS – dist-upgrade aborts with held broken packages

🟠 High   ⏱ 5–30 min  Last verified: 18 October 2021 Affected versions: Ubuntu 18.04 LTS Ubuntu 18.04 Ubuntu 18.04.6 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention […]

Read more
Debian 11 — ruby-redcarpet — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — ruby-redcarpet — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 October 2021 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-26298 Upstream summary: Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. […]

Read more
CHAT