CentOS Stream

CentOS Stream 9 — lua — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — lua — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 April 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:0957 Related CVEs: CVE-2021-43519 CVE-2021-44964 CVE-2022-33099 CVE-2022-28805 Upstream summary: The lua packages provide support for Lua, a powerful light-weight programming language designed for extending applications. Lua is also frequently used as […]

Read more
CentOS Stream 9 — virt-v2v — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — virt-v2v — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 April 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:7968 Related CVEs: CVE-2022-2211 Upstream summary: The virt-v2v package provides a tool for converting virtual machines to use the KVM (Kernel-based Virtual Machine) hypervisor or AlmaLinux Enterprise Virtualization. The tool modifies […]

Read more
CentOS Stream 9 — freetype — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — freetype — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 March 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:8340 Related CVEs: CVE-2022-27404 CVE-2022-27405 CVE-2022-27406 Upstream summary: FreeType is a free, high-quality, portable font engine that can open and manage font files. FreeType loads, hints, and renders individual glyphs efficiently. […]

Read more
CentOS Stream 9 — bzip2 — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — bzip2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 March 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2025:0925 Related CVEs: CVE-2019-12900 Upstream summary: The bzip2 packages contain a freely available, high-quality data compressor. It provides both standalone compression and decompression utilities, as well as a shared library for […]

Read more
CentOS Stream 9 — python-wheel — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — python-wheel — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 March 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6712 Related CVEs: CVE-2022-40898 Upstream summary: Wheel is the reference implementation of the Python wheel packaging standard, as defined in PEP 427. Security Fix(es): * python-wheel: remote attackers can cause denial […]

Read more
CentOS Stream 9 — zlib — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — zlib — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 February 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:7314 Related CVEs: CVE-2022-37434 Upstream summary: The zlib packages provide a general-purpose lossless data compression library that is used by many different programs. Security Fix(es): * zlib: a heap-based buffer over-read […]

Read more
CentOS Stream 9 — libfastjson — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — libfastjson — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 February 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6431 Related CVEs: CVE-2020-12762 Upstream summary: The libfastjson library provides essential JavaScript Object Notation (JSON) handling functions. The library enables users to construct JSON objects in C, output them as JSON-formatted […]

Read more
CentOS Stream 9 — rpm — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — rpm — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 February 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2024:0463 Related CVEs: CVE-2021-35937 CVE-2021-35938 CVE-2021-35939 Upstream summary: The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Security […]

Read more
CentOS Stream 9 — gmp — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — gmp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 January 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2023:6661 Related CVEs: CVE-2021-43618 Upstream summary: The gmp packages contain GNU MP, a library for arbitrary precision arithmetics, signed integers operations, rational numbers, and floating point numbers. Security Fix(es): * gmp: […]

Read more
CentOS Stream 9 — mingw-zlib — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — mingw-zlib — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 December 2021 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALSA-2022:8420 Related CVEs: CVE-2018-25032 Upstream summary: The zlib packages provide a general-purpose lossless data compression library that is used by many different programs. Security Fix(es): * zlib: A flaw found in […]

Read more
CHAT