CentOS Stream 9

CentOS Stream 9 — pmix — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — pmix — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2199 Related CVEs: CVE-2023-41915 Upstream summary: The Process Management Interface (PMI) provides process management functions for MPI implementations. PMI Exascale (PMIx) provides an extended version of the PMI standard specifically designed […]

Read more
CentOS Stream 9 — perl-HTTP-Tiny — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — perl-HTTP-Tiny — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6542 Related CVEs: CVE-2023-31486 Upstream summary: HTTP::Tiny is a small and simple HTTP/1.1 client written in Perl. Security Fix(es): * http-tiny: insecure TLS cert default (CVE-2023-31486) For more details about the […]

Read more
CentOS Stream 9 — bash — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — bash — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:0340 Related CVEs: CVE-2022-3715 Upstream summary: The bash packages provide Bash (Bourne-again shell), which is the default shell for AlmaLinux. Security Fix(es): * bash: a heap-buffer-overflow in valid_parameter_transform (CVE-2022-3715) For more […]

Read more
CentOS Stream 9 — autotrace — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — autotrace — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:2589 Related CVEs: CVE-2022-32323 Upstream summary: AutoTrace is a program for converting bitmaps to vector graphics. Security Fix(es): * autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c (CVE-2022-32323) For more details […]

Read more
CentOS Stream 9 — zziplib — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — zziplib — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:20838 Related CVEs: CVE-2018-17828 CVE-2020-18770 Upstream summary: The zziplib is a lightweight library to easily extract data from zip files. Security Fix(es): * zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c […]

Read more
CentOS Stream 9 — ncurses — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — ncurses — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6698 Related CVEs: CVE-2023-29491 Upstream summary: The ncurses (new curses) library routines are a terminal-independent method of updating character screens with reasonable optimization. The ncurses packages contain support utilities including a […]

Read more
CentOS Stream 9 — fwupd — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — fwupd — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:2487 Related CVEs: CVE-2022-3287 CVE-2022-34301 CVE-2022-34302 CVE-2022-34303 Upstream summary: The fwupd packages provide a service that allows session software to update device firmware. Security Fix(es): * fwupd: world readable password in […]

Read more
CentOS Stream 9 — fribidi — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — fribidi — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:8011 Related CVEs: CVE-2022-25308 CVE-2022-25309 CVE-2022-25310 Upstream summary: FriBidi is a library to handle bidirectional scripts (for example Hebrew, Arabic), so that the display is done in the proper way, while […]

Read more
CentOS Stream 9 — wpa_supplicant — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — wpa_supplicant — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2517 Related CVEs: CVE-2023-52160 Upstream summary: The wpa_supplicant packages contain an 802.1X Supplicant with support for WEP, WPA, WPA2 (IEEE 802.11i / RSN), and various EAP authentication methods. They implement key […]

Read more
CentOS Stream 9 — tpm2-tss — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — tpm2-tss — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6685 Related CVEs: CVE-2023-22745 Upstream summary: The tpm2-tss packages provide the Intel implementation of the Trusted Platform Module (TPM) 2.0 System API library. This library enables programs to interact with TPM […]

Read more
CHAT