Package Management

Debian 11 — dietlibc — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — dietlibc — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 April 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2002-0391 CVE-2003-0028 CVE-2012-1577 Upstream summary: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, […]

Read more
Debian 11 — fdupes — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — fdupes — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 April 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-48682 Upstream summary: In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink. Table of contents Symptom & Impact Environment & […]

Read more
Debian 11 — passportjs — vulnerability — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — passportjs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 April 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2022-25896 Upstream summary: This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed. Table of […]

Read more
Ubuntu 20.04 — linux-hwe-5.13 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — linux-hwe-5.13 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 April 2022 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-5493-2 Related CVEs: CVE-2022-28388 CVE-2022-21123 CVE-2022-21125 CVE-2022-21166 CVE-2022-1158 CVE-2022-1966 CVE-2022-1972 CVE-2022-21499  +12 more Upstream summary: It was discovered that the 8 Devices USB2CAN interface implementation in the Linux kernel did […]

Read more
Ubuntu 14.04 — libxstream-java — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 14.04

Ubuntu 14.04 — libxstream-java — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 April 2022 Affected versions: Ubuntu 14.04 (trusty) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6978-1 Related CVEs: CVE-2016-3674 CVE-2020-26217 CVE-2020-26258 CVE-2020-26259 CVE-2021-21341 CVE-2021-21342 CVE-2021-21343 CVE-2021-21344  +12 more Upstream summary: It was discovered that XStream incorrectly handled parsing of certain crafted XML documents. A remote […]

Read more
SLES 15 — xmlbeans — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — xmlbeans — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 April 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3875-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-23926 Upstream summary: The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious […]

Read more
openSUSE Tumbleweed — libsl0 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Tumbleweed

openSUSE Tumbleweed — libsl0 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2022-45142 CVE-2021-44758 CVE-2022-41916 CVE-2021-3671 Upstream summary: The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by […]

Read more
Oracle Linux 8 — grafana-pcp — vulnerability — patch and remediation guide — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — grafana-pcp — vulnerability — patch and remediation guide (ELSA-2022-7648)

🟡 Medium   ⏱ 10–30 min  Last verified: 20 April 2022 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: ELSA advisory ELSA-2022-7648 Related CVEs: CVE-2022-32148 CVE-2022-30632 CVE-2022-30635 CVE-2022-30630 CVE-2022-1705 CVE-2022-30631 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – […]

Read more
Debian 11 — nss — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Debian 11

Debian 11 — nss — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 April 2022 Affected versions: Debian 11 (bullseye) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2009-2404 CVE-2009-2408 CVE-2009-2409 CVE-2009-3555 CVE-2010-3170 CVE-2010-3173 CVE-2011-3389 CVE-2011-3640  +12 more Upstream summary: Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as […]

Read more
CHAT