CentOS Stream 9

CentOS Stream 9 — mod_auth_openidc — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mod_auth_openidc — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 May 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:9396 Related CVEs: CVE-2025-3891 CVE-2025-31492 CVE-2024-24814 CVE-2022-23527 CVE-2023-28625 Upstream summary: The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as […]

Read more
CentOS Stream 9 — transfig — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — transfig — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 May 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2026:0700 Related CVEs: CVE-2025-46397 Upstream summary: The transfig utility creates a makefile which translates FIG (created by xfig) or PIC figures into a specified LaTeX graphics language (for example, PostScript(TM)). Transfig […]

Read more
CentOS Stream 9 — unbound — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — unbound — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 May 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:11849 Related CVEs: CVE-2025-5994 CVE-2024-1488 CVE-2023-50387 CVE-2023-50868 CVE-2024-8508 CVE-2022-3204 CVE-2022-30698 CVE-2022-30699 Upstream summary: The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): * unbound: Unbound […]

Read more
CentOS Stream 9 — brotli — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — brotli — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 May 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2026:2042 Related CVEs: CVE-2025-6176 Upstream summary: Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd […]

Read more
CentOS Stream 9 — wireshark — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — wireshark — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 May 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:23142 Related CVEs: CVE-2025-13499 CVE-2023-0666 CVE-2023-0668 CVE-2023-2855 CVE-2023-2856 CVE-2023-2858 CVE-2023-2952 CVE-2022-3190 Upstream summary: The wireshark packages contain a network protocol analyzer used to capture and browse the traffic running on a […]

Read more
CentOS Stream 9 — less — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — less — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:3513 Related CVEs: CVE-2024-32487 CVE-2022-48624 CVE-2022-46663 Upstream summary: The "less" utility is a text file browser that resembles "more", but allows users to move backwards in the file as well as […]

Read more
CentOS Stream 9 — mod_md — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mod_md — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:23739 Related CVEs: CVE-2025-55753 Upstream summary: This module manages common properties of domains for one or more virtual hosts. Specifically it can use the ACME protocol to automate certificate provisioning. Certificates […]

Read more
CentOS Stream 9 — osbuild — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — osbuild — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:7118 Related CVEs: CVE-2024-1394 CVE-2024-34158 CVE-2024-9355 Upstream summary: A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images […]

Read more
CentOS Stream 9 — mod_http2 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mod_http2 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:1872 Related CVEs: CVE-2024-27316 CVE-2023-25690 CVE-2025-49630 CVE-2023-43622 CVE-2023-45802 CVE-2024-36387 Upstream summary: The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers. Security Fix(es): […]

Read more
CHAT