The 5.15.16 stable kernel update contains a number of important fixes across the tree.
Archive for January, 2022
Security fix for CVE-2021-45931
RedHat: RHSA-2022-0230:03 Moderate: Red Hat OpenShift Enterprise Logging
An update is now available for OpenShift Logging (5.2.6) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Debian: DSA-5053-1: pillow security update
Multiple security issues were discovered in Pillow, a Python imaging library, which could result in denial of service and potentially the execution of arbitrary code if malformed images are processed.
Ubuntu 5248-1: Thunderbird vulnerabilities
Several security issues were fixed in Thunderbird.
Security fix for CVE-2021-45930
Rebase to version 2.4.3
Debian: DSA-5052-1: usbview security update
Matthias Gerstner reported that usbview, a USB device viewer, does not properly handle authorization in the PolicyKit policy configuration, which could result in root privilege escalation.
USBView could be made to crash or run programs as an administrator.
Ubuntu 5246-1: Thunderbird vulnerabilities
Several security issues were fixed in Thunderbird.
RedHat: RHSA-2022-0223:02 Moderate: Red Hat Integration Camel-K 1.6.3
A minor version update (from 1.6.2 to 1.6.3) is now available for Red Hat Integration Camel K that includes bug fixes. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact
RedHat: RHSA-2022-0227:04 Moderate: Red Hat OpenShift Enterprise Logging
An update is now available for OpenShift Logging (5.3.3) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2022-0225:02 Moderate: Red Hat OpenShift Enterprise Logging
An update is now available for OpenShift Logging (5.0.12) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2022-0226:04 Moderate: Red Hat OpenShift Enterprise Logging
An update is now available for OpenShift Logging (5.1.7) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2022-0222:02 Moderate: Red Hat Integration Camel Extensions
A security update to Red Hat Integration Camel Extensions for Quarkus 2.2 is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Red Hat Product Security has rated this update as having an impact of
Debian: DSA-5051-1: aide security update
David Bouman discovered a heap-based buffer overflow vulnerability in the base64 functions of aide, an advanced intrusion detection system, which can be triggered via large extended file attributes or ACLs. This may result in denial of service or privilege escalation.
RedHat: RHSA-2022-0205:02 Moderate: Red Hat Data Grid 8.2.3 security update
An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
RedHat: RHSA-2022-0216:06 Low: Red Hat JBoss Enterprise Application
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
Debian: DSA-5050-1: linux security update
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Debian: DSA-5049-1: flatpak security update
Several vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps. CVE-2021-43860
AIDE could be made to crash or run programs as an administrator if it opened a specially crafted file.
The 5.15.15 stable kernel update contains a number of important fixes across the tree.
Fedora 35: texlive-base 2022-639b9d2b85
Update to newer version of arara with newer log4j. Severity is low because exploiting this locally would be challenging.
Ubuntu 5242-1: Open vSwitch vulnerability
Open vSwitch could be made to hang or crash if it received specially crafted network traffic.
Ubuntu 0084-1: Linux kernel vulnerability
A security issue was fixed in the kernel.
curl could be made to expose sensitive information if it received a specially crafted input.
Several security issues were fixed in QtSvg.
Ubuntu 5240-1: Linux kernel vulnerability
The system could be made to crash or run programs as an administrator.
RedHat: RHSA-2022-0188:07 Important: kernel security and bug fix update
An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
RedHat: RHSA-2022-0190:04 Moderate: Satellite 6.10.2 Async Bug Fix Update
Updated Satellite 6.10 packages that fix several bugs are now available for Red Hat Satellite. 2. Relevant releases/architectures: Red Hat Satellite 6.10 – noarch, x86_64