CentOS Stream

CentOS Stream 9 — libguestfs-winsupport — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libguestfs-winsupport — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 June 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:2179 Related CVEs: CVE-2021-46790 CVE-2022-30784 CVE-2022-30786 CVE-2022-30788 CVE-2022-30789 CVE-2022-40284 Upstream summary: The libguestfs-winsupport package adds support for Windows guests to libguestfs, a set of tools and libraries allowing users to access […]

Read more
CentOS Stream 9 — libinput — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libinput — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 June 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:5257 Related CVEs: CVE-2022-1215 Upstream summary: libinput is a library that handles input devices for display servers and other applications that need to directly deal with input devices. Security Fix(es): * […]

Read more
CentOS Stream 9 — python-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — python-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 June 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:15874 Related CVEs: CVE-2023-49083 CVE-2023-23931 Upstream summary: Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports […]

Read more
CentOS Stream 9 — device-mapper-multipath — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — device-mapper-multipath — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 June 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:8453 Related CVEs: CVE-2022-3787 CVE-2022-41974 CVE-2022-41973 Upstream summary: The device-mapper-multipath packages provide tools that use the device-mapper multipath kernel module to manage multipath devices. Security Fix(es): * device-mapper-multipath: Regression of CVE-2022-41974 […]

Read more
CentOS Stream 9 — libjpeg-turbo — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libjpeg-turbo — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2295 Related CVEs: CVE-2021-29390 CVE-2021-46822 Upstream summary: The libjpeg-turbo packages contain a library of functions for manipulating JPEG images. They also contain simple client programs for accessing the libjpeg functions. These […]

Read more
CentOS Stream 9 — xterm — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — xterm — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:14075 Related CVEs: CVE-2022-24130 CVE-2022-45063 Upstream summary: The xterm program is a terminal emulator for the X Window System. It provides DEC VT102 and Tektronix 4014 compatible terminals for programs that […]

Read more
CentOS Stream 9 — mutt — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mutt — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2290 Related CVEs: CVE-2023-4874 CVE-2023-4875 CVE-2022-1328 Upstream summary: Mutt is a low resource, highly configurable, text-based MIME e-mail client. Mutt supports most e-mail storing formats, such as mbox and Maildir, as […]

Read more
CentOS Stream 9 — pmix — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — pmix — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2199 Related CVEs: CVE-2023-41915 Upstream summary: The Process Management Interface (PMI) provides process management functions for MPI implementations. PMI Exascale (PMIx) provides an extended version of the PMI standard specifically designed […]

Read more
CentOS Stream 9 — perl-HTTP-Tiny — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — perl-HTTP-Tiny — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6542 Related CVEs: CVE-2023-31486 Upstream summary: HTTP::Tiny is a small and simple HTTP/1.1 client written in Perl. Security Fix(es): * http-tiny: insecure TLS cert default (CVE-2023-31486) For more details about the […]

Read more
CentOS Stream 9 — bash — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — bash — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:0340 Related CVEs: CVE-2022-3715 Upstream summary: The bash packages provide Bash (Bourne-again shell), which is the default shell for AlmaLinux. Security Fix(es): * bash: a heap-buffer-overflow in valid_parameter_transform (CVE-2022-3715) For more […]

Read more
CHAT