Package Management

FreeBSD 13 — musicpd — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — musicpd — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MPD — buffer overflows in http output Upstream summary: The MPD project reports: httpd: fix two buffer overflows in IcyMetaData length calculation Table of contents Symptom & Impact Environment & […]

Read more
How to Harden the Linux Kernel with sysctl on RHEL 7 — step-by-step RHEL 7 tutorial on Progressive Robot

How to Harden the Linux Kernel with sysctl on RHEL 7

How to Harden the Linux Kernel with sysctl on RHEL 7 The Linux kernel exposes hundreds of tunable parameters through the /proc/sys/ virtual filesystem, and the sysctl utility provides a clean interface for reading and setting those values at runtime and persistently across reboots. Many of these parameters have direct security implications: they control whether […]

Read more
Ubuntu 20.04 — openssl-ibmca — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — openssl-ibmca — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 May 2021 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-6046-1 Related CVEs: https://launchpad.net/bugs/2015454 Upstream summary: It was discovered that OpenSSL-ibmca incorrectly handled certain RSA decryption. An attacker could possibly use this issue to expose sensitive information. Table of contents […]

Read more
FreeBSD 13 — mariadb104-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mariadb104-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MariaDB — Nullpointer dereference Related CVEs: CVE-2018-25032 CVE-2019-1543 CVE-2019-1547 CVE-2019-15601 CVE-2019-17543 CVE-2019-2730 CVE-2019-2731 CVE-2019-2737  +12 more Upstream summary: The MariaDB project reports: MariaDB Server is vulnerable to Denial of Service. […]

Read more
Debian 10 — opensmtpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Debian 10

Debian 10 — opensmtpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 May 2021 Affected versions: Debian 10 (buster) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2020-7247 CVE-2020-8794 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & […]

Read more
Amazon Linux 2 — kernel-livepatch-4.14.225-169.362 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-4.14.225-169.362 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2021-051 Related CVEs: CVE-2021-33034 Upstream summary: A use-after-free flaw was found in hci_send_acl in the bluetooth host controller interface (HCI) in Linux kernel, where a local attacker with an access […]

Read more
How to Configure Suricata IDS/IPS on RHEL 8 — step-by-step RHEL 8 tutorial on Progressive Robot

How to Configure Suricata IDS/IPS on RHEL 8

Suricata is a high-performance, open-source network threat detection engine that can operate as an Intrusion Detection System (IDS) to alert on suspicious traffic, or as an Intrusion Prevention System (IPS) to actively block it. On RHEL 8, Suricata integrates naturally with firewalld‘s NFQUEUE target for inline packet inspection, and its Lua scripting and Eve JSON […]

Read more
Oracle Linux 8 — Installer Automatically Enables Ethernet Over USB Network Interface During a PXE Installation — diagnosis and fix on Oracle Linux 8

Oracle Linux 8 — Installer Automatically Enables Ethernet Over USB Network Interface During a PXE Installation

🟠 High   ⏱ 5–30 min  Last verified: 27 May 2021 Affected versions: Oracle Linux 8 📖 ~4 min read  •  Source: Oracle Bug 31888490 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan […]

Read more
CHAT