CentOS Stream

CentOS Stream 9 — autotrace — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — autotrace — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:2589 Related CVEs: CVE-2022-32323 Upstream summary: AutoTrace is a program for converting bitmaps to vector graphics. Security Fix(es): * autotrace: heap-buffer overflow via the ReadImage() at input-bmp.c (CVE-2022-32323) For more details […]

Read more
CentOS Stream 9 — zziplib — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — zziplib — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:20838 Related CVEs: CVE-2018-17828 CVE-2020-18770 Upstream summary: The zziplib is a lightweight library to easily extract data from zip files. Security Fix(es): * zziplib: directory traversal in unzzip_cat in the bins/unzzipcat-mem.c […]

Read more
CentOS Stream 9 — ncurses — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — ncurses — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6698 Related CVEs: CVE-2023-29491 Upstream summary: The ncurses (new curses) library routines are a terminal-independent method of updating character screens with reasonable optimization. The ncurses packages contain support utilities including a […]

Read more
CentOS Stream 9 — fwupd — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — fwupd — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 May 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:2487 Related CVEs: CVE-2022-3287 CVE-2022-34301 CVE-2022-34302 CVE-2022-34303 Upstream summary: The fwupd packages provide a service that allows session software to update device firmware. Security Fix(es): * fwupd: world readable password in […]

Read more
CentOS Stream 9 — fribidi — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — fribidi — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:8011 Related CVEs: CVE-2022-25308 CVE-2022-25309 CVE-2022-25310 Upstream summary: FriBidi is a library to handle bidirectional scripts (for example Hebrew, Arabic), so that the display is done in the proper way, while […]

Read more
CentOS Stream 9 — wpa_supplicant — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — wpa_supplicant — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2517 Related CVEs: CVE-2023-52160 Upstream summary: The wpa_supplicant packages contain an 802.1X Supplicant with support for WEP, WPA, WPA2 (IEEE 802.11i / RSN), and various EAP authentication methods. They implement key […]

Read more
CentOS Stream 9 — tpm2-tss — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — tpm2-tss — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6685 Related CVEs: CVE-2023-22745 Upstream summary: The tpm2-tss packages provide the Intel implementation of the Trusted Platform Module (TPM) 2.0 System API library. This library enables programs to interact with TPM […]

Read more
CentOS Stream 9 — bluez — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — bluez — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:9413 Related CVEs: CVE-2023-27349 CVE-2023-44431 CVE-2023-45866 CVE-2023-50229 CVE-2023-50230 CVE-2023-51580 CVE-2023-51589 CVE-2023-51592  +2 more Upstream summary: The bluez packages contain the following utilities for use in Bluetooth applications: hcitool, hciattach, hciconfig, bluetoothd, […]

Read more
CentOS Stream 9 — ignition — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — ignition — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:8126 Related CVEs: CVE-2022-1706 Upstream summary: Ignition is a utility used to manipulate systems during the initramfs. This includes partitioning disks, formatting partitions, writing files (regular files, systemd units, etc.), and […]

Read more
CentOS Stream 9 — motif — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — motif — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 April 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2217 Related CVEs: CVE-2023-43788 CVE-2023-43789 Upstream summary: The motif packages include the Motif shared libraries needed to run applications which are dynamically linked against Motif, as well as MWM, the Motif […]

Read more
CHAT