CentOS Stream

CentOS Stream 9 — less — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — less — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:3513 Related CVEs: CVE-2024-32487 CVE-2022-48624 CVE-2022-46663 Upstream summary: The "less" utility is a text file browser that resembles "more", but allows users to move backwards in the file as well as […]

Read more
Common Problems 126973

CentOS Stream 10 – Common Problem 176 – Diagnosis and Fix

🟡 Medium   ⏱ 5–30 min  Last verified: 21 April 2025 Affected versions: CentOS Stream 10 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors […]

Read more
CentOS Stream 9 — mod_md — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mod_md — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:23739 Related CVEs: CVE-2025-55753 Upstream summary: This module manages common properties of domains for one or more virtual hosts. Specifically it can use the ACME protocol to automate certificate provisioning. Certificates […]

Read more
CentOS Stream 9 — osbuild — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — osbuild — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:7118 Related CVEs: CVE-2024-1394 CVE-2024-34158 CVE-2024-9355 Upstream summary: A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images […]

Read more
CentOS Stream 9 — mod_http2 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mod_http2 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:1872 Related CVEs: CVE-2024-27316 CVE-2023-25690 CVE-2025-49630 CVE-2023-43622 CVE-2023-45802 CVE-2024-36387 Upstream summary: The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers. Security Fix(es): […]

Read more
Common Problems 127142

CentOS Stream 10 – Common Problem 143 – Diagnosis and Fix

🟠 High   ⏱ 5–30 min  Last verified: 16 April 2025 Affected versions: CentOS Stream 10 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors […]

Read more
CentOS Stream 9 — mpg123 — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mpg123 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:11242 Related CVEs: CVE-2024-10573 Upstream summary: The mpg123 packages contain real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2, and 3 (most commonly MPEG 1.0 layer 3 also known as […]

Read more
CentOS Stream 9 — perl-YAML-LibYAML — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — perl-YAML-LibYAML — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 April 2025 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:9330 Related CVEs: CVE-2025-40908 Upstream summary: Kirill Siminov's "libyaml" is arguably the best YAML implementation. The C library is written precisely to the YAML 1.1 specification. It was originally bound to […]

Read more
CentOS Stream 10 — grub2 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 10

CentOS Stream 10 — grub2 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 April 2025 Affected versions: CentOS Stream 10 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2026:4649 Related CVEs: CVE-2025-61662 CVE-2024-45776 CVE-2024-45781 CVE-2025-0622 CVE-2025-0677 CVE-2025-1118 Upstream summary: The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader […]

Read more
CHAT