Aggregator

LSN-0116-1: Kernel Live Patch Security Notice

3 days 19 hours ago
In the Linux kernel, the following vulnerability has been resolved: net: atlantic: eliminate double free in error handling logic Driver has a logic leak in ring data allocation/free, where aq_ring_free could be called multiple times on same ring, if system is under stress and got memory allocation error. In the Linux kernel, the following vulnerability has been resolved: sctp: properly validate chunk size in sctp_sf_ootb() A size validation fix similar to that in Commit 50619dbf8db7 ('sctp: add size validation when walking chunks') is also required in sctp_sf_ootb() to address a crash reported by syzbot: BUG: KMSAN: uninit-value in sctp_sf_ootb+0x7f5/0xce0 net/sctp/sm_statefuns.c:3712 sctp_sf_ootb+0x7f5/0xce0 net/sctp/sm_statefuns.c:3712 sctp_do_sm+0x181/0x93d0 net/sctp/sm_sideeffect.c:1166 sctp_endpoint_bh_rcv+0xc38/0xf90 net/sctp/endpointola.c:407 sctp_inq_push+0x2ef/0x380 net/sctp/inqueue.c:88 sctp_rcv+0x3831/0x3b20 net/sctp/input.c:243 sctp4_rcv+0x42/0x50 net/sctp/protocol.c:1159 ip_protocol_deliver_rcu+0xb51/0x13d0 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x336/0x500 net/ipv4/ip_input.c:233)(CVE-2024-50299). In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. In the Linux kernel, the following vulnerability has been resolved: ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit After an insertion in TNC, the tree might split and cause a node to change its `znode->parent`. In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent NULL dereference in nfsd4_process_cb_update() @ses is initialized to NULL. In the Linux kernel, the following vulnerability has been resolved: padata: fix UAF in padata_reorder A bug was found when run ltp test: BUG: KASAN: slab-use-after-free in padata_find_next+0x29/0x1a0 Read of size 4 at addr ffff88bbfe003524 by task kworker/u113:2/3039206 CPU: 0 PID: 3039206 Comm: kworker/u113:2 Kdump: loaded Not tainted 6.6.0+ Workqueue: pdecrypt_parallel padata_parallel_worker Call Trace: dump_stack_lvl+0x32/0x50 print_address_description.constprop.0+0x6b/0x3d0 print_report+0xdd/0x2c0 kasan_report+0xa5/0xd0 padata_find_next+0x29/0x1a0 padata_reorder+0x131/0x220 padata_parallel_worker+0x3d/0xc0 process_one_work+0x2ec/0x5a0 If 'mdelay(10)' is added before calling 'padata_find_next' in the 'padata_reorder' function, this issue could be reproduced easily with ltp test (pcrypt_aead01). In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right after unlock_task_sighand().

cef-142.0.10^chromium142.0.7444.162-2.fc43

4 days ago
FEDORA-2025-604e02ca72 Packages in this update:
  • cef-142.0.10^chromium142.0.7444.162-2.fc43
Update description:

Update to 142.0.7444.162

  • High CVE-2025-12725: Out of bounds write in WebGPU
  • High CVE-2025-12726: Inappropriate implementation in Views
  • High CVE-2025-12727: Inappropriate implementation in V8
  • Medium CVE-2025-12728: Inappropriate implementation in Omnibox
  • Medium CVE-2025-12729: Inappropriate implementation in Omnibox
  • High CVE-2025-12428: Type Confusion in V8
  • High CVE-2025-12429: Inappropriate implementation in V8
  • High CVE-2025-12430: Object lifecycle issue in Media
  • High CVE-2025-12431: Inappropriate implementation in Extensions
  • High CVE-2025-12432: Race in V8
  • High CVE-2025-12433: Inappropriate implementation in V8
  • High CVE-2025-12036: Inappropriate implementation in V8
  • Medium CVE-2025-12434: Race in Storage
  • Medium CVE-2025-12435: Incorrect security UI in Omnibox
  • Medium CVE-2025-12436: Policy bypass in Extensions
  • Medium CVE-2025-12437: Use after free in PageInfo
  • Medium CVE-2025-12438: Use after free in Ozone
  • Medium CVE-2025-12439: Inappropriate implementation in App-Bound Encryption
  • Low CVE-2025-12440: Inappropriate implementation in Autofill
  • Medium CVE-2025-12441: Out of bounds read in V8
  • Medium CVE-2025-12443: Out of bounds read in WebXR
  • Low CVE-2025-12444: Incorrect security UI in Fullscreen UI
  • Low CVE-2025-12445: Policy bypass in Extensions
  • Low CVE-2025-12446: Incorrect security UI in SplitView
  • Low CVE-2025-12447: Incorrect security UI in Omnibox

cef-142.0.14^chromium142.0.7444.162-1.fc42

4 days ago
FEDORA-2025-58193e3850 Packages in this update:
  • cef-142.0.14^chromium142.0.7444.162-1.fc42
Update description:

Update to 142.0.7444.162

  • High CVE-2025-12725: Out of bounds write in WebGPU
  • High CVE-2025-12726: Inappropriate implementation in Views
  • High CVE-2025-12727: Inappropriate implementation in V8
  • Medium CVE-2025-12728: Inappropriate implementation in Omnibox
  • Medium CVE-2025-12729: Inappropriate implementation in Omnibox
  • High CVE-2025-12428: Type Confusion in V8
  • High CVE-2025-12429: Inappropriate implementation in V8
  • High CVE-2025-12430: Object lifecycle issue in Media
  • High CVE-2025-12431: Inappropriate implementation in Extensions
  • High CVE-2025-12432: Race in V8
  • High CVE-2025-12433: Inappropriate implementation in V8
  • High CVE-2025-12036: Inappropriate implementation in V8
  • Medium CVE-2025-12434: Race in Storage
  • Medium CVE-2025-12435: Incorrect security UI in Omnibox
  • Medium CVE-2025-12436: Policy bypass in Extensions
  • Medium CVE-2025-12437: Use after free in PageInfo
  • Medium CVE-2025-12438: Use after free in Ozone
  • Medium CVE-2025-12439: Inappropriate implementation in App-Bound Encryption
  • Low CVE-2025-12440: Inappropriate implementation in Autofill
  • Medium CVE-2025-12441: Out of bounds read in V8
  • Medium CVE-2025-12443: Out of bounds read in WebXR
  • Low CVE-2025-12444: Incorrect security UI in Fullscreen UI
  • Low CVE-2025-12445: Policy bypass in Extensions
  • Low CVE-2025-12446: Incorrect security UI in SplitView
  • Low CVE-2025-12447: Incorrect security UI in Omnibox

USN-7871-1: FFmpeg vulnerability

4 days 4 hours ago
It was discovered that FFmpeg incorrectly handled memory allocation in the ALS audio decoder. If a user was tricked into loading a crafted media file, a remote attacker could possibly use this issue to make FFmpeg crash, resulting in a denial of service.

kubernetes1.33-1.33.6-1.fc41

5 days 4 hours ago
FEDORA-2025-e282b00383 Packages in this update:
  • kubernetes1.33-1.33.6-1.fc41
Update description:
  • Update to release v1.33.6
  • Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523
  • Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610
  • Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528
  • Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478, rhbz#2410739
  • Resolves: rhbz#2411118, rhbz#2411377, rhbz#2412570, rhbz#2412589
  • Resolves: rhbz#2412804
  • Upstream fixes

kubernetes1.33-1.33.6-1.fc42

5 days 6 hours ago
FEDORA-2025-362709ff5e Packages in this update:
  • kubernetes1.33-1.33.6-1.fc42
Update description:
  • Update to release v1.33.6
  • Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523
  • Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610
  • Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528
  • Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478, rhbz#2410739
  • Resolves: rhbz#2411118, rhbz#2411377, rhbz#2412570, rhbz#2412589
  • Resolves: rhbz#2412804
  • Upstream fixes

kubernetes1.33-1.33.6-1.fc43

5 days 6 hours ago
FEDORA-2025-298add9246 Packages in this update:
  • kubernetes1.33-1.33.6-1.fc43
Update description:
  • Update to release v1.33.6
  • Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523
  • Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610
  • Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528
  • Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478, rhbz#2410739
  • Resolves: rhbz#2411118, rhbz#2411377, rhbz#2412570, rhbz#2412589
  • Resolves: rhbz#2412804
  • Upstream fixes

kubernetes1.33-1.33.6-1.fc44

5 days 7 hours ago
FEDORA-2025-fe1d8025b0 Packages in this update:
  • kubernetes1.33-1.33.6-1.fc44
Update description:

Automatic update for kubernetes1.33-1.33.6-1.fc44.

Changelog * Thu Nov 13 2025 Bradley G Smith <bradley.g.smith@gmail.com> - 1.33.6-1 - Update to release v1.33.6 - Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523 - Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610 - Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528 - Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478, rhbz#2410739 - Resolves: rhbz#2411118, rhbz#2411377, rhbz#2412570, rhbz#2412589 - Resolves: rhbz#2412804 - Upstream fixes

kubernetes1.34-1.34.2-1.fc41

5 days 11 hours ago
FEDORA-2025-ebce31df24 Packages in this update:
  • kubernetes1.34-1.34.2-1.fc41
Update description:
  • Update to release v1.34.2
  • Resolves: rhbz#2398589, rhbz#2398850, rhbz#2399251, rhbz#2399524
  • Resolves: rhbz#2407790, rhbz#2408060, rhbz#2408317, rhbz#2408611
  • Resolves: rhbz#2408674, rhbz#2408732, rhbz#2409239, rhbz#2409529
  • Resolves: rhbz#2409790, rhbz#2410204, rhbz#2410479, rhbz#2410740
  • Resolves: rhbz#2411120, rhbz#2411378, rhbz#2411636 rhbz#2412590
  • Resolves: rhbz#2412805
  • Upstream fixes

kubernetes1.34-1.34.2-1.fc42

5 days 12 hours ago
FEDORA-2025-4c576d1bd9 Packages in this update:
  • kubernetes1.34-1.34.2-1.fc42
Update description:
  • Update to release v1.34.2
  • Resolves: rhbz#2398589, rhbz#2398850, rhbz#2399251, rhbz#2399524
  • Resolves: rhbz#2407790, rhbz#2408060, rhbz#2408317, rhbz#2408611
  • Resolves: rhbz#2408674, rhbz#2408732, rhbz#2409239, rhbz#2409529
  • Resolves: rhbz#2409790, rhbz#2410204, rhbz#2410479, rhbz#2410740
  • Resolves: rhbz#2411120, rhbz#2411378, rhbz#2411636 rhbz#2412590
  • Resolves: rhbz#2412805
  • Upstream fixes

kubernetes1.34-1.34.2-1.fc43

5 days 12 hours ago
FEDORA-2025-f32b1debd8 Packages in this update:
  • kubernetes1.34-1.34.2-1.fc43
Update description:
  • Update to release v1.34.2
  • Resolves: rhbz#2398589, rhbz#2398850, rhbz#2399251, rhbz#2399524
  • Resolves: rhbz#2407790, rhbz#2408060, rhbz#2408317, rhbz#2408611
  • Resolves: rhbz#2408674, rhbz#2408732, rhbz#2409239, rhbz#2409529
  • Resolves: rhbz#2409790, rhbz#2410204, rhbz#2410479, rhbz#2410740
  • Resolves: rhbz#2411120, rhbz#2411378, rhbz#2411636 rhbz#2412590
  • Resolves: rhbz#2412805
  • Upstream fixes