Package Management

Ubuntu 16.04 — apache-log4j2 — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — apache-log4j2 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 May 2022 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5192-2 Related CVEs: CVE-2021-44228 Upstream summary: USN-5192-1 fixed a vulnerability in Apache Log4j 2. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: Chen Zhaojun discovered […]

Read more
SLES 15 — apache-commons-configuration2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache-commons-configuration2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 May 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2022-33980 Upstream summary: Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where […]

Read more
openSUSE Tumbleweed — libksba8 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libksba8 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:2627-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-3515 CVE-2022-47629 CVE-2014-9087 CVE-2016-4574 CVE-2016-4579 Upstream summary: A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The […]

Read more
Oracle Linux 8 — polkit — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — polkit — vulnerability — patch and remediation guide (ELSA-2022-0267)

🟠 High   ⏱ 15–60 min  Last verified: 24 May 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-0267 Related CVEs: CVE-2021-4034 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
Oracle Linux 8 — parfait:0.5 — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — parfait:0.5 — vulnerability — patch and remediation guide (ELSA-2022-0290)

🟠 High   ⏱ 15–60 min  Last verified: 24 May 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-0290 Related CVEs: CVE-2022-23305 CVE-2022-23302 CVE-2022-23307 CVE-2021-4104 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches […]

Read more
Oracle Linux 8 — Unbreakable Enterprise kernel — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — Unbreakable Enterprise kernel — vulnerability — patch and remediation guide (ELSA-2021-9371)

🟠 High   ⏱ 15–60 min  Last verified: 24 May 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2021-9371 Related CVEs: CVE-2021-33909 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
IBM AIX 7.3 — CVE-2021-29888 — vulnerability — patch and remediation guide — diagnosis and fix on IBM AIX 7.3

IBM AIX 7.3 — CVE-2021-29888 — vulnerability — patch and remediation guide

🟠 High   ⏱ 30–90 min  Last verified: 24 May 2022 Affected versions: IBM AIX 7.3 📖 ~4 min read  •  Source: NVD CVE-2021-29888, IBM Support Bulletin CVE: CVE-2021-29888 NVD summary: IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from […]

Read more
CentOS Stream 9 — qatzip — vulnerability — patch and remediation guide — diagnosis and fix on CentOS Stream 9

CentOS Stream 9 — qatzip — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 May 2022 Affected versions: CentOS Stream 9 📖 ~4 min read  •  Source: AlmaLinux/RHEL advisory ALBA-2022:8256 Related CVEs: CVE-2022-36369 Upstream summary: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section. Table of contents Symptom & Impact Environment […]

Read more
CHAT