nvme: Fix DMA reentrancy use-after-free (CVE-2021-3929)
Archive for September 22nd, 2022
Fedora 36: thunderbird 2022-feb7bdf6b2
Update to 102.3.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2022-42/ ; https://www.thunderbird.net/en- US/thunderbird/102.3.0/releasenotes/
In the September 2022 survey we received responses from 1,129,251,133 sites across 271,625,260 unique domains, and 12,252,171 web-facing computers. This month all three metrics have decreased since August, with a loss of 5.82 million sites, 115,512 unique domains and 113,356 web-facing computers.
nginx had the largest increase in web-facing computers, gaining 28,887 (+0.56%) this month. OpenResty had the second largest increase, gaining 6,008 (+3.54%) web-facing computers, along with a gain of 339,813 (+0.86%) domains and 149,893 (+2.35%) active sites. Google showed strong growth in all metrics, with an increase of 5,127 web-facing computers, 211,135 (+8.83%) domains, and 895,225 (+4.71%) active sites.
Within the top million busiest sites, Apache lost 0.21pp of its market share. Despite this, it continues to be the most commonly used web server in the top million. nginx also continued its long-term downward trend, but lost only 0.14pp, further closing the gap between Apache and nginx. The gap now stands at 4,499 sites, a decrease of 13.8% since last month. Meanwhile, Cloudflare’s growth continues, with its market share in the top million increasing by 0.25pp.
Apache also experienced a loss in overall market share, losing 414,684 (-0.94%) active sites and 18,156 computers (-0.49%). The only other developers to lose active sites were Microsoft and nginx, with losses of 58,443 (-1.01%) and (-0.10%) respectively.
LiteSpeed’s market share continues to increase at a steady rate, with it gaining 92,704 (+1.14%) domains and 70,146 (+0.73%) active sites this month.
Vendor news
- njs 0.7.7, the scripting language used to extend nginx, was released on 30 August 2022, with new features and bug fixes.
- Lighttpd 1.4.67 was released, with a variety of bug fixes.
- Amazon AWS opened a new region in the United Arab Emirates. This is the second AWS region in the Middle East, joining the existing region in Bahrain.
- Microsoft’s Windows Server 2022 is now generally available.
- Cloudflare published an article about the development of its purpose built HTTP Proxy, Pingora.
Developer | August 2022 | Percent | September 2022 | Percent | Change |
---|---|---|---|---|---|
nginx | 328,204,211 | 28.91% | 319,472,149 | 28.29% | -0.62 |
Apache | 256,787,976 | 22.62% | 247,026,645 | 21.88% | -0.75 |
OpenResty | 92,609,414 | 8.16% | 92,645,981 | 8.20% | 0.05 |
Cloudflare | 77,538,226 | 6.83% | 83,638,115 | 7.41% | 0.58 |
Debian: DSA-5236-1: expat security update
Rhodri James discovered a heap use-after-free vulnerability in the doContent function in Expat, an XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code, if a malformed XML file is processed.
Python could be made to redirect web traffic if its http.server received a specially crafted request.
Ubuntu 5631-1: libjpeg-turbo vulnerabilities
Several security issues were fixed in libjpeg-turbo.
Ubuntu 5632-1: OAuthLib vulnerability
OAuthLib could be made to crash if it received specially crafted network traffic.
Ubuntu 5634-1: Linux kernel (OEM) vulnerability
The system could be made to crash if it received specially crafted network traffic.
Ubuntu 5633-1: Linux kernel vulnerabilities
Several security issues were fixed in the Linux kernel.
Ubuntu 5628-1: etcd vulnerabilities
Several security issues were fixed in etcd.
Ubuntu 5630-1: Linux kernel (Raspberry Pi) vulnerabilities
Several security issues were fixed in the Linux kernel.
Debian: DSA-5235-1: bind9 security update
Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2022-2795
This month, Tokyo was the stage of our latest WebPros Partner Day, sponsored by Acronis and Virtuozzo. Smoothly organized in the Shinagawa venue close to Tokyo’s sparkling business district, WebPros was eager to return to form for yet another informative day of sharing and caring – a slice of the good life – with our dedicated partners from the east and beyond. As we still find ourselves amidst an ongoing Covid pandemic, we wish to sincerely thank the brave Godzilla’s who managed to come out to make it to this event. Bravo! For those who couldn’t, stay put: we have…
The post After Japan Partner Day 2022 appeared first on Plesk.
RedHat: RHSA-2022-6681:01 Important: OpenShift Virtualization 4.9.6 Images
Red Hat OpenShift Virtualization release 4.9.6 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,