CentOS Stream

CentOS Stream 9 — doxygen — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — doxygen — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 March 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:1329 Related CVEs: CVE-2020-11023 Upstream summary: Doxygen can generate an online class browser (in HTML) and/or a reference manual (in LaTeX) from a set of documented source files. The documentation is […]

Read more
CentOS Stream 9 — qt5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — qt5 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 March 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6369 Related CVEs: CVE-2023-32573 CVE-2023-33285 CVE-2023-34410 CVE-2023-37369 CVE-2023-38197 CVE-2022-25255 Upstream summary: Qt is a software toolkit for developing applications. Security Fix(es): * qt: buffer over-read via a crafted reply from a […]

Read more
CentOS Stream 9 — procps-ng — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — procps-ng — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 February 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6705 Related CVEs: CVE-2023-4016 Upstream summary: The procps-ng packages contain a set of system utilities that provide system information, including ps, free, skill, pkill, pgrep, snice, tload, top, uptime, vmstat, w, […]

Read more
CentOS Stream 9 — python3.11-cryptography — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — python3.11-cryptography — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 February 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2337 Related CVEs: CVE-2023-49083 Upstream summary: The python-cryptography packages contain a Python Cryptographic Authority's (PyCA's) cryptography library, which provides cryptographic primitives and recipes to Python developers. Security Fix(es): * python-cryptography: NULL-dereference […]

Read more
CentOS Stream 9 — perl-File-Find-Rule — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — perl-File-Find-Rule — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 February 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:9517 Related CVEs: CVE-2011-10007 Upstream summary: File::Find::Rule is a friendlier interface to File::Find. It allows you to build rules which specify the desired files and directories. Security Fix(es): * perl-file-find-rule: File::Find::Rule […]

Read more
CentOS Stream 9 — kernel-rt — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — kernel-rt — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 February 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:5091 Related CVEs: CVE-2023-1637 CVE-2023-20593 CVE-2023-21102 CVE-2023-31248 CVE-2023-3390 CVE-2023-35001 CVE-2023-3610 CVE-2023-3776  +12 more Upstream summary: The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely […]

Read more
CentOS Stream 9 — dmidecode — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — dmidecode — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 February 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:5061 Related CVEs: CVE-2023-30630 Upstream summary: The dmidecode packages provide utilities for extracting Intel 64 and Intel Itanium hardware information from the system BIOS or Extensible Firmware Interface (EFI), depending on […]

Read more
CentOS Stream 9 — libksba — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libksba — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 January 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:0626 Related CVEs: CVE-2022-47629 CVE-2022-3515 Upstream summary: KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building […]

Read more
CentOS Stream 9 — python3.11-pip — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — python3.11-pip — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 January 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6324 Related CVEs: CVE-2007-4559 Upstream summary: pip is a package management system used to install and manage software packages written in Python. Many packages can be found in the Python Package […]

Read more
CentOS Stream 9 — harfbuzz — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — harfbuzz — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 January 2023 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:2410 Related CVEs: CVE-2023-25193 CVE-2022-33068 Upstream summary: HarfBuzz is an implementation of the OpenType Layout engine. Security Fix(es): * harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks (CVE-2023-25193) For […]

Read more
CHAT