CentOS Stream 9

CentOS Stream 9 — bluez — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — bluez — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:9413 Related CVEs: CVE-2023-27349 CVE-2023-44431 CVE-2023-45866 CVE-2023-50229 CVE-2023-50230 CVE-2023-51580 CVE-2023-51589 CVE-2023-51592  +2 more Upstream summary: The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, […]

Read more
CentOS Stream 9 — ignition — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — ignition — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:8126 Related CVEs: CVE-2022-1706 Upstream summary: Ignition is a utility used to manipulate systems during the initramfs. This includes partitioning disks, formatting partitions, writing files (regular files, systemd units, etc.), and […]

Read more
CentOS Stream 9 — motif — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — motif — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2217 Related CVEs: CVE-2023-43788 CVE-2023-43789 Upstream summary: The motif packages include the Motif shared libraries needed to run applications which are dynamically linked against Motif, as well as MWM, the Motif […]

Read more
CentOS Stream 9 — gcc-toolset-13-gcc — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gcc-toolset-13-gcc — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:1309 Related CVEs: CVE-2020-11023 Upstream summary: The gcc-toolset-13-gcc13 package contains the GNU Compiler Collection version 13. Security Fix(es): * jquery: Untrusted code execution via <option> tag in HTML passed to DOM […]

Read more
CentOS Stream 9 — mingw-pixman — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mingw-pixman — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2525 Related CVEs: CVE-2022-44638 Upstream summary: Pixman is a pixel manipulation library for the X Window System and Cairo. Security Fix(es): * pixman: Integer overflow in pixman_sample_floor_y leading to heap out-of-bounds […]

Read more
CentOS Stream 9 — golang-github-cpuguy83-md2man — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — golang-github-cpuguy83-md2man — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 March 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:2592 Related CVEs: CVE-2022-41715 Upstream summary: go-md2man converts markdown into roff (man pages). Security Fix(es): * golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) For more details about the security […]

Read more
CentOS Stream 9 — nss — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — nss — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 March 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:1368 Related CVEs: CVE-2023-0767 CVE-2023-6135 CVE-2023-5388 Upstream summary: Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Security Fix(es): […]

Read more
CentOS Stream 9 — squashfs-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — squashfs-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 March 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2396 Related CVEs: CVE-2021-40153 CVE-2021-41072 Upstream summary: SquashFS is a highly compressed read-only file system for Linux. These packages contain the utilities for manipulating squashfs file systems. Security Fix(es): * squashfs-tools: […]

Read more
CentOS Stream 9 — yajl — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — yajl — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 March 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6551 Related CVEs: CVE-2023-33460 CVE-2022-24795 Upstream summary: Yet Another JSON Library (YAJL) is a small event-driven (SAX-style) JSON parser written in ANSI C, and a small validating JSON generator. Security Fix(es): […]

Read more
CentOS Stream 9 — swtpm — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — swtpm — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 March 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:8100 Related CVEs: CVE-2022-23645 Upstream summary: SWTPM is a TPM emulator built on libtpms providing TPM functionality for QEMU VMs. Security Fix(es): * swtpm: Unchecked header size indicator against expected size […]

Read more
CHAT