CentOS Stream

CentOS Stream 9 — apr-util — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — apr-util — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 June 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:3147 Related CVEs: CVE-2022-25147 Upstream summary: The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and other projects. apr-util is a library which provides additional […]

Read more
CentOS Stream 9 — gcc — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gcc — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 June 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:1346 Related CVEs: CVE-2020-11023 Upstream summary: The gcc packages provide compilers for C, C++, Java, Fortran, Objective C, and Ada 95 GNU, as well as related support libraries. Security Fix(es): * […]

Read more
CentOS Stream 9 — conmon — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — conmon — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 May 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:2222 Related CVEs: CVE-2022-41717 Upstream summary: Conmon is an OCI container runtime monitor. Security Fix(es): * golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) For more […]

Read more
CentOS Stream 9 — qatzip — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — qatzip — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 May 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALBA-2022:8256 Related CVEs: CVE-2022-36369 Upstream summary: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section. Table of contents Symptom & Impact Environment […]

Read more
CentOS Stream 9 — tbb — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — tbb — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 May 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:1210 Related CVEs: CVE-2020-11023 Upstream summary: Threading Building Blocks (TBB) is a C++ runtime library that abstracts the low-level threading details necessary for optimal multi-core performance. Security Fix(es): * jquery: Untrusted […]

Read more
CentOS Stream 9 — usbguard — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — usbguard — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 April 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:0303 Related CVEs: CVE-2019-25058 Upstream summary: The USBGuard software framework provides system protection against intrusive USB devices by implementing basic whitelisting and blacklisting capabilities based on device attributes. To enforce a […]

Read more
CentOS Stream 9 — pesign — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — pesign — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 April 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:1067 Related CVEs: CVE-2022-3560 Upstream summary: The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools. Security Fix(es): * pesign: Local privilege escalation on […]

Read more
CentOS Stream 9 — protobuf-c — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — protobuf-c — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 April 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6621 Related CVEs: CVE-2022-48468 Upstream summary: The protobuf-c packages provide C bindings for Google's Protocol Buffers. Security Fix(es): * protobuf-c: unsigned integer overflow in parse_required_member (CVE-2022-48468) For more details about the […]

Read more
CentOS Stream 9 — gcc-toolset-14-gcc — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gcc-toolset-14-gcc — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 April 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:1300 Related CVEs: CVE-2020-11023 Upstream summary: The gcc-toolset-14-gcc13 package contains the GNU Compiler Collection version 14. Security Fix(es): * jquery: Untrusted code execution via <option> tag in HTML passed to DOM […]

Read more
CHAT