CentOS Stream 9

CentOS Stream 9 — qt5-qtbase — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — qt5-qtbase — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:4623 Related CVEs: CVE-2024-39936 CVE-2025-5455 CVE-2023-51714 CVE-2024-25580 CVE-2023-32573 CVE-2023-33285 CVE-2023-34410 CVE-2023-37369  +1 more Upstream summary: Qt is a software toolkit for developing applications. The qt5-base packages contain base tools for string, […]

Read more
CentOS Stream 9 — python3.11-setuptools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — python3.11-setuptools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:5279 Related CVEs: CVE-2024-6345 CVE-2025-47273 Upstream summary: Setuptools is a collection of enhancements to the Python 3 distutils that allow you to more easily build and distribute Python 3 packages, especially […]

Read more
CentOS Stream 9 — udisks2 — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — udisks2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:15018 Related CVEs: CVE-2025-8067 Upstream summary: The Udisks project provides a daemon, tools, and libraries to access and manipulate disks, storage devices, and technologies. Security Fix(es): * udisks: Out-of-bounds read in […]

Read more
CentOS Stream 9 — microcode_ctl — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — microcode_ctl — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:7043 Related CVEs: CVE-2024-28047 CVE-2024-31157 CVE-2024-39279 CVE-2023-22655 CVE-2023-28746 CVE-2023-38575 CVE-2023-39368 CVE-2023-43490  +2 more Upstream summary: The microcode_ctl packages provide microcode updates for Intel and AMD processors. Security Fix(es): * microcode_ctl: Improper […]

Read more
CentOS Stream 9 — jmc — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — jmc — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2026:0752 Related CVEs: CVE-2025-66566 Upstream summary: JDK Mission Control is a powerful profiler for HotSpot JVMs and has an advanced set of tools that enables efficient and detailed analysis of the […]

Read more
CentOS Stream 9 — openjpeg2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — openjpeg2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:7309 Related CVEs: CVE-2024-56826 CVE-2024-56827 CVE-2022-1122 Upstream summary: OpenJPEG is an open source library for reading and writing image files in JPEG2000 format. Security Fix(es): * openjpeg: heap buffer overflow in […]

Read more
CentOS Stream 9 — libnbd — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libnbd — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:6757 Related CVEs: CVE-2024-7383 CVE-2023-5215 CVE-2023-5871 Upstream summary: Network Block Device (NBD) is a protocol for accessing Block Devices (hard disks and disk-like devices) over a Network. The libnbd is a […]

Read more
CentOS Stream 9 — util-linux — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — util-linux — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2026:1913 Related CVEs: CVE-2025-14104 Upstream summary: The util-linux packages contain a large variety of low-level system utilities that are necessary for a Linux system to function. Among others, these include the […]

Read more
CentOS Stream 9 — postgresql-jdbc — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — postgresql-jdbc — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:1436 Related CVEs: CVE-2024-1597 CVE-2022-41946 CVE-2022-31197 Upstream summary: PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL […]

Read more
CentOS Stream 9 — flatpak — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — flatpak — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 February 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:9449 Related CVEs: CVE-2024-42472 CVE-2024-32462 CVE-2023-28100 CVE-2023-28101 Upstream summary: Bubblewrap (/usr/bin/bwrap) is a core execution engine for unprivileged containers that works as a setuid binary on kernels without user namespaces. Security […]

Read more
CHAT