CentOS Stream 9

CentOS Stream 9 — binutils — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — binutils — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 October 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:23343 Related CVEs: CVE-2025-11083 CVE-2022-4285 Upstream summary: The binutils packages provide a collection of binary utilities for the manipulation of object code in various object file formats. It includes the ar, […]

Read more
CentOS Stream 9 — opentelemetry-collector — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — opentelemetry-collector — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 September 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2026:4177 Related CVEs: CVE-2025-61726 CVE-2025-68121 CVE-2025-61729 CVE-2025-68156 CVE-2025-4673 CVE-2025-22871 Upstream summary: Collector with the supported components for a AlmaLinux build of OpenTelemetry Security Fix(es): * golang: net/url: Memory exhaustion in query […]

Read more
CentOS Stream 9 — python-jinja2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — python-jinja2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 September 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:3406 Related CVEs: CVE-2025-27516 CVE-2024-56326 CVE-2024-34064 CVE-2024-22195 Upstream summary: Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. […]

Read more
CentOS Stream 9 — php-pecl-rrd — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — php-pecl-rrd — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 September 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2026:1409 Related CVEs: CVE-2025-1220 CVE-2025-14177 CVE-2025-14178 CVE-2025-14180 CVE-2025-1735 CVE-2025-6491 CVE-2024-11235 CVE-2025-1217  +12 more Upstream summary: PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * […]

Read more
CentOS Stream 9 — gnutls — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gnutls — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 September 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2026:4188 Related CVEs: CVE-2025-14831 CVE-2025-9820 CVE-2025-32988 CVE-2025-32989 CVE-2025-32990 CVE-2025-6395 CVE-2024-12243 CVE-2024-28834  +6 more Upstream summary: The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and […]

Read more
CentOS Stream 9 — open-vm-tools — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — open-vm-tools — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 September 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:17428 Related CVEs: CVE-2025-41244 CVE-2023-34058 CVE-2023-34059 CVE-2023-20900 CVE-2022-31676 CVE-2025-22247 CVE-2023-20867 Upstream summary: The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of […]

Read more
CentOS Stream 9 — haproxy — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — haproxy — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 September 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:21693 Related CVEs: CVE-2025-11230 CVE-2023-40225 CVE-2023-45539 CVE-2023-0836 CVE-2023-0056 CVE-2023-25725 Upstream summary: The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications. Security Fix(es): * haproxy: denial […]

Read more
CentOS Stream 9 — gcc-toolset-15-binutils — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gcc-toolset-15-binutils — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 August 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2026:1359 Related CVEs: CVE-2025-11083 Upstream summary: Binutils is a collection of binary utilities, including ar (for creating, modifying and extracting from archives), as (a family of GNU assemblers), gprof (for displaying […]

Read more
CentOS Stream 9 — delve — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — delve — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 August 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:3773 Related CVEs: CVE-2024-34156 CVE-2025-68121 CVE-2025-58183 Upstream summary: The Go Programming Language. Security Fix(es): * encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic […]

Read more
CentOS Stream 9 — keylime-agent-rust — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — keylime-agent-rust — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 August 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:7313 Related CVEs: CVE-2025-24898 Upstream summary: Rust agent for Keylime Security Fix(es): * rust-openssl: rust openssl ssl::select_next_proto use after free (CVE-2025-24898) For more details about the security issue(s), including the impact, […]

Read more
CHAT