Moderate: ipa security update
GNU libmicrohttpd is a small C library that makes it easy to run an HTTP server as part of another application.<br>Security Fix(es):<br><li> libmicrohttpd: remote DoS (CVE-2023-27371)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: oniguruma security update
Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.Security Fix(es): QEMU: hcd-ehci: DMA reentrancy issue leads to use-after-free (CVE-2021-3750) QEMU: e1000e: heap use-after-free in e1000ewritepackettoguest() (CVE-2023-3019) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: fwupd security update
GNU libmicrohttpd is a small C library that makes it easy to run an HTTP server as part of another application.Security Fix(es): libmicrohttpd: remote DoS (CVE-2023-27371) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: kernel security, bug fix, and enhancement update
Moderate: opencryptoki security update
Moderate: fwupd security update
Moderate: kernel security, bug fix, and enhancement update
Moderate: java-17-openjdk security update
Moderate: java-1.8.0-openjdk security update
Moderate: java-11-openjdk security update
Moderate: opencryptoki security update
Moderate: yajl security update
Moderate: sssd security and bug fix update
Moderate: yajl security update
Moderate: protobuf security update
Moderate: kernel security and bug fix update
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.Security Fix(es): nghttp2: CONTINUATION frames DoS (CVE-2024-28182,VU#421644.5) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: ghostscript security update
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. <br>Security Fix(es):<br><li> dovecot: using a large number of address headers may trigger a denial of service (CVE-2024-23184)</li> <li> dovecot: very large headers can cause resource exhaustion when parsing message (CVE-2024-23185)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): dovecot: using a large number of address headers may trigger a denial of service (CVE-2024-23184) dovecot: very large headers can cause resource exhaustion when parsing message (CVE-2024-23185) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: python3.11 security update
Moderate: OpenIPMI security update
Moderate: OpenIPMI security update
libuv is a multi-platform support library with a focus on asynchronous I/O. Security Fix(es): libuv: Improper Domain Lookup that potentially leads to SSRF attacks (CVE-2024-24806) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: java-17-openjdk security update for RHEL 8.6, 8.8, 8.10, 9.4 and 9.5
Moderate: java-17-openjdk security update for RHEL 9.0 and 9.2
Moderate: java-21-openjdk security update for RHEL 8.10, 9.4 and 9.5