Critical: lasso security update
Critical: nginx security update
Critical: nginx security update
Critical: samba security update
Critical: kernel security update
Important: unbound security update
Important: kernel security update
Important: unbound security update
Important: bind9.16 security update
Important: bind security update
EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. Security Fix(es): edk2: Buffer overflow when handling Server ID option from a DHCPv6 proxy Advertise message (CVE-2023-45235) EDK2: heap buffer overflow in Tcg2MeasureGptTable() (CVE-2022-36763) EDK2: heap buffer overflow in Tcg2MeasurePeImage() (CVE-2022-36764) edk2: Integer underflow when processing IANA/IATA options in a DHCPv6 Advertise message (CVE-2023-45229) edk2: Out of Bounds read when handling a ND Redirect message with truncated options (CVE-2023-45231) edk2: Infinite loop when parsing unknown options in the Destination Options header (CVE-2023-45232) edk2: Infinite loop when parsing a PadN option in the Destination Options header (CVE-2023-45233) openssl: Excessive time spent checking DH keys and parameters (CVE-2023-3446) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.4 Release Notes linked from the References section.
Important: kernel security, bug fix, and enhancement update
Important: glibc security update
Important: glibc security update
Important: glibc security update
Important: glibc security update
Important: python39:3.9 and python39-devel:3.9 security update
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The basepackages include the Lightweight Directory Access Protocol (LDAP) server andcommand-line utilities for server administration.Security Fix(es): 389-ds-base: potential denial of service via specially crafted kerberos AS-REQ request (CVE-2024-3657) 389-ds-base: Malformed userPassword may cause crash at domodify in slapd/modify.c (CVE-2024-2199) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.Security Fix(es): flatpak: sandbox escape via RequestBackground portal (CVE-2024-32462) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer the CVE page(s) listed in the References section.
Important: python3.11 security update
Important: python3.11 security update
Important: python3.9 security update
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.107 and Runtime 8.0.7.Security Fix(es): dotnet: DoS in System.Text.Json (CVE-2024-30105) dotnet: DoS in ASP.NET Core 8 (CVE-2024-35264) dotnet: DoS when parsing X.509 Content and ObjectIdentifiers (CVE-2024-38095) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.107 and Runtime 8.0.7.Security Fix(es): dotnet: DoS in System.Text.Json (CVE-2024-30105) dotnet: DoS in ASP.NET Core 8 (CVE-2024-35264) dotnet: DoS when parsing X.509 Content and ObjectIdentifiers (CVE-2024-38095) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: kernel security update
Important: bind and bind-dyndb-ldap security update
Important: kernel security update
Important: kernel security update
Important: kernel security update