started · updated
Linux distributions release major security updates for kernel and software flaws
Multiple major Linux distributions, including Ubuntu, Debian, Fedora, Red Hat, Rocky Linux, AlmaLinux, and SUSE, have released significant security updates to address a wide range of vulnerabilities.
The updates cover over 150 CVEs, addressing issues such as privilege escalation, denial of service, and remote code execution. Notable vulnerabilities include heap overflows in GStreamer audio and video plugins and a tarfile extraction filter bypass affecting the Python ecosystem, which could allow malicious archives to escape target directories.
Kernel patches have been issued for various subsystems, including memory management, networking, and virtualization. Administrators are advised to note that specific builds, such as Ubuntu cloud or Raspberry Pi kernels, may require careful maintenance due to kernel ABI changes that necessitate rebuilding out-of-tree drivers. While many updates can be applied via standard package managers, the volume of fixes for Python, Node.js, and GStreamer suggests that scheduled maintenance windows are recommended.
Entities
Debian · Linux kernel · Red Hat · SUSE · Ubuntu