CentOS Stream 9

CentOS Stream 9 — libksba — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libksba — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 January 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:0626 Related CVEs: CVE-2022-47629 CVE-2022-3515 Upstream summary: KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building […]

Read more
CentOS Stream 9 — python3.11-pip — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — python3.11-pip — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 January 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6324 Related CVEs: CVE-2007-4559 Upstream summary: pip is a package management system used to install and manage software packages written in Python. Many packages can be found in the Python Package […]

Read more
CentOS Stream 9 — harfbuzz — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — harfbuzz — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 January 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2410 Related CVEs: CVE-2023-25193 CVE-2022-33068 Upstream summary: HarfBuzz is an implementation of the OpenType Layout engine. Security Fix(es): * harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks (CVE-2023-25193) For […]

Read more
CentOS Stream 9 — python-mako — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — python-mako — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 January 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:2258 Related CVEs: CVE-2022-40023 Upstream summary: Mako is a template library written in Python. It provides a familiar, non-XML syntax which compiles into Python modules for maximum performance. Security Fix(es): * […]

Read more
CentOS Stream 9 — logrotate — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — logrotate — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 December 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:8393 Related CVEs: CVE-2022-1348 Upstream summary: The logrotate utility simplifies the administration of multiple log files by allowing their automatic rotation, compression, removal, and mailing. Security Fix(es): * logrotate: potential DoS […]

Read more
CentOS Stream 9 — speex — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — speex — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 December 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:7979 Related CVEs: CVE-2020-23903 Upstream summary: Speex is a patent-free compression format designed especially for speech. It is specialized for voice communications at low bit-rates. Security Fix(es): * speex: divide by […]

Read more
CentOS Stream 9 — xz — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — xz — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 December 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:4940 Related CVEs: CVE-2022-1271 Upstream summary: XZ Utils is an integrated collection of user-space file compression utilities based on the Lempel-Ziv-Markov chain algorithm (LZMA), which performs lossless data compression. The algorithm […]

Read more
CentOS Stream 9 — pixman — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — pixman — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 December 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:7754 Related CVEs: CVE-2022-44638 Upstream summary: Pixman is a pixel manipulation library for the X Window System and Cairo. Security Fix(es): * pixman: Integer overflow in pixman_sample_floor_y leading to heap out-of-bounds […]

Read more
CentOS Stream 9 — file — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — file — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 December 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2512 Related CVEs: CVE-2022-48554 Upstream summary: The file command is used to identify a particular file according to the type of data the file contains. It can identify many different file […]

Read more
CentOS Stream 9 — gdb — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gdb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 December 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6372 Related CVEs: CVE-2021-3826 Upstream summary: The GNU Debugger (GDB) allows users to debug programs written in various programming languages including C, C++, and Fortran. Security Fix(es): * libiberty: Heap/stack buffer […]

Read more
CHAT