CentOS Stream

CentOS Stream 9 — gstreamer1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gstreamer1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 September 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:7178 Related CVEs: CVE-2024-0444 CVE-2024-4453 Upstream summary: The gstreamer1 packages contain a streaming media framework, based on graphs of filters which operate on media data. Security Fix(es): * gstreamer: EXIF Metadata […]

Read more
CentOS Stream 9 — ansible-core — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — ansible-core — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 September 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2246 Related CVEs: CVE-2024-0690 Upstream summary: Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software […]

Read more
CentOS Stream 9 — gstreamer1-rtsp-server — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gstreamer1-rtsp-server — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 September 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:7178 Related CVEs: CVE-2024-0444 CVE-2024-4453 Upstream summary: The gstreamer1 packages contain a streaming media framework, based on graphs of filters which operate on media data. Security Fix(es): * gstreamer: EXIF Metadata […]

Read more
CentOS Stream 9 — dotnet7.0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — dotnet7.0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 September 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2843 Related CVEs: CVE-2024-30045 CVE-2024-30046 CVE-2024-21386 CVE-2024-21404 CVE-2024-0056 CVE-2024-0057 CVE-2024-21319 CVE-2023-44487  +12 more Upstream summary: .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several […]

Read more
CentOS Stream 9 — tpm2-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — tpm2-tools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 September 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:9424 Related CVEs: CVE-2024-29038 CVE-2024-29039 Upstream summary: The tpm2-tools packages add a set of utilities for management and utilization of Trusted Platform Module (TPM) 2.0 devices from user space. Security Fix(es): […]

Read more
CentOS Stream 9 — mod_proxy_cluster — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mod_proxy_cluster — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 August 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:9434 Related CVEs: CVE-2024-10306 CVE-2023-41081 CVE-2023-6710 Upstream summary: The mod_proxy_cluster module is a plugin for the Apache HTTP Server that provides load-balancer functionality. Security Fix(es): * mod_proxy_cluster: mod_proxy_cluster unauthorized MCMP requests […]

Read more
CentOS Stream 9 — libgcrypt — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libgcrypt — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 August 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:9404 Related CVEs: CVE-2024-2236 Upstream summary: The libgcrypt library provides general-purpose implementations of various cryptographic algorithms. Security Fix(es): * libgcrypt: vulnerable to Marvin Attack (CVE-2024-2236) For more details about the security […]

Read more
CentOS Stream 9 — aardvark-dns — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — aardvark-dns — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 August 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:7094 Related CVEs: CVE-2024-8418 Upstream summary: Authoritative DNS server for A/AAAA container records Forwards other request to configured resolvers. Read more about configuration in `src/backend/mod.rs`. Security Fix(es): * containers/aardvark-dns: TCP Query […]

Read more
CentOS Stream 9 — nano — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — nano — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 July 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:9430 Related CVEs: CVE-2024-5742 Upstream summary: GNU nano is a small and friendly text editor. Security Fix(es): * nano: running `chmod` and `chown` on the filename allows malicious user to replace […]

Read more
CentOS Stream 9 — OpenIPMI — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — OpenIPMI — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 July 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:8037 Related CVEs: CVE-2024-42934 Upstream summary: The OpenIPMI packages provide command-line tools and utilities to access platform information using Intelligent Platform Management Interface (IPMI). System administrators can use OpenIPMI to manage […]

Read more
CHAT