CentOS Stream

CentOS Stream 9 — firefox — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — firefox — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 10 July 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:1485 Related CVEs: CVE-2023-5388 CVE-2024-0743 CVE-2024-2607 CVE-2024-2608 CVE-2024-2610 CVE-2024-2611 CVE-2024-2612 CVE-2024-2614  +12 more Upstream summary: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update […]

Read more
CentOS Stream 9 — exfatprogs — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — exfatprogs — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 July 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2437 Related CVEs: CVE-2023-45897 Upstream summary: The exfatprogs package contains utilities for formatting and repairing exFAT filesystems. Security Fix(es): * exfatprogs: exfatprogs allows out-of-bounds memory access (CVE-2023-45897) For more details about […]

Read more
CentOS Stream 9 — libtasn1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libtasn1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 July 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:7077 Related CVEs: CVE-2024-12133 CVE-2021-46848 Upstream summary: A library that provides Abstract Syntax Notation One (ASN.1, as specified by the X.680 ITU-T recommendation) parsing and structures management, and Distinguished Encoding Rules […]

Read more
CentOS Stream 9 — libwebp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libwebp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 July 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:5214 Related CVEs: CVE-2023-4863 CVE-2023-1999 Upstream summary: The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital […]

Read more
CentOS Stream 9 — keepalived — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — keepalived — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 July 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:0917 Related CVEs: CVE-2024-41184 Upstream summary: The keepalived utility provides simple and robust facilities for load balancing and high availability. The load balancing framework relies on the well-known and widely used […]

Read more
CentOS Stream 9 — pki-core — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — pki-core — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 July 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:4165 Related CVEs: CVE-2023-4727 CVE-2022-2414 CVE-2022-2393 Upstream summary: The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System. Security Fix(es): * dogtag ca: token authentication bypass vulnerability […]

Read more
CentOS Stream 9 — tracker-miners — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — tracker-miners — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 June 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:7712 Related CVEs: CVE-2023-5557 Upstream summary: Tracker is a powerful desktop-neutral first class object database, tag/metadata database and search tool. This package contains various miners and metadata extractors for tracker. Security […]

Read more
CentOS Stream 9 — gnome-shell-extensions — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gnome-shell-extensions — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 June 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:9114 Related CVEs: CVE-2024-36472 Upstream summary: GNOME Shell acts as a compositing manager for the desktop, and displays both application windows and other objects. It provides core interface functions like switching […]

Read more
CentOS Stream 9 — shadow-utils — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — shadow-utils — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 June 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:20559 Related CVEs: CVE-2024-56433 CVE-2023-4641 Upstream summary: The shadow-utils packages include programs for converting UNIX password files to the shadow password format, as well as utilities for managing user and group […]

Read more
CentOS Stream 9 — rust — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — rust — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 June 2024 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:4634 Related CVEs: CVE-2023-38497 Upstream summary: Rust Toolset provides the Rust programming language compiler rustc, the cargo build tool and dependency manager, and required libraries. Security Fix(es): * rust-cargo: cargo does […]

Read more
CHAT