Zeros312
oval:org.rockylinux.rlsa:def:20247977 | RLSA-2024:7977: firefox security update (Important) | Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Security Fix(es):
* firefox: Use-after-free in Animation timeline (128.3.1 ESR Chemspill) (CVE-2024-9680)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-10-25 00:00:00+03:00 | 2024-10-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:7977', 'https://errata.rockylinux.org/RLSA-2024:7977'] | 0e2ca40fa59fccc87867c3702eda39cd7d8c715187a0fa96dbb34a5a472a1980 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246989 | RLSA-2024:6989: expat security update (Moderate) | Expat is a C library for parsing XML documents.
Security Fix(es):
* libexpat: Negative Length Parsing Vulnerability in libexpat (CVE-2024-45490)
* libexpat: Integer Overflow or Wraparound (CVE-2024-45491)
* libexpat: integer overflow (CVE-2024-45492)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-09-30 00:00:00+03:00 | 2024-09-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6989', 'https://errata.rockylinux.org/RLSA-2024:6989'] | 03bcc1cd360bd04a1febda9e0bd22fbeb8c00f99817ba54af666b2b11b403a3d | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20245079 | RLSA-2024:5079: libtiff security update (Moderate) | The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.
Security Fix(es):
* libtiff: Heap-based buffer overflow in ChopUpSingleUncompressedStrip in tif_dirread.c (CVE-2018-15209)
* libtiff: Buffer Overflow via /libtiff/tools/tiffcrop.c (CVE-2023-25433)
* libtiff: heap-based buffer overflow in cpStripToTile() in tools/tiffcp.c (CVE-2023-6228)
* libtiff: Segment fault in libtiff in TIFFReadRGBATileExt() leading to denial of service (CVE-2023-52356)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-08-21 00:00:00+03:00 | 2024-08-21 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:5079', 'https://errata.rockylinux.org/RLSA-2024:5079'] | eb7900c683666a527dd2a85b524c104e78a0ef5874cf8cdffab28bf39d387d83 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20233661 | RLSA-2023:3661: texlive security update (Important) | The texlive packages contain TeXLive, an implementation of TeX for Linux or UNIX systems.
Security Fix(es):
* texlive: arbitrary code execution allows document complied with older version (CVE-2023-32700)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2023-06-24 00:00:00+03:00 | 2023-06-24 00:00:00+03:00 | ['Rocky Linux 8', 'Rocky Linux 9'] | ['RLSA-2023:3661', 'https://errata.rockylinux.org/RLSA-2023:3661'] | 1e9336c877471e6b095022c947c78f5275ff4b0595e403319f0672fea60b252e | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20248359 | RLSA-2024:8359: python39 (Moderate) | Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.
Security Fix(es):
* python: cpython: tarfile: ReDos via excessive backtracking while parsing header values (CVE-2024-6232)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-10-25 00:00:00+03:00 | 2024-10-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:8359', 'https://errata.rockylinux.org/RLSA-2024:8359'] | 4399f66ccd9223a7cb57edd9cb25fcc26f106a603621b87fba454c375d1acad1 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246986 | RLSA-2024:6986: nano security update (Low) | GNU nano is a small and friendly text editor.
Security Fix(es):
* nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file (CVE-2024-5742)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Low | 2024-09-30 00:00:00+03:00 | 2024-09-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6986', 'https://errata.rockylinux.org/RLSA-2024:6986'] | 9785a50089a4c33ff31989308434c5e6dde8232ae5c19f7e0fc6939b8d24ce5c | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246148 | RLSA-2024:6148: nodejs (Moderate) | Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* node-tar: denial of service while parsing a tar file due to lack of folders depth validation (CVE-2024-28863)
* nodejs: Bypass network import restriction via data URL (CVE-2024-22020)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-09-17 00:00:00+03:00 | 2024-09-17 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6148', 'https://errata.rockylinux.org/RLSA-2024:6148'] | a9e7f3b34d2fad8cf72170e79d8bb26a764fca9a83de64ae041f0bff1119b4d2 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246422 | RLSA-2024:6422: bubblewrap and flatpak security update (Important) | Bubblewrap (/usr/bin/bwrap) is a core execution engine for unprivileged containers that works as a setuid binary on kernels without user namespaces.
Security Fix(es):
* flatpak: Access to files outside sandbox for apps using persistent= (--persist) (CVE-2024-42472)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-09-17 00:00:00+03:00 | 2024-09-17 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6422', 'https://errata.rockylinux.org/RLSA-2024:6422'] | a53b2704841d311a1b33548d98498a2312ea0e0b40bdeeddd3654bbce4a5b6cd | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20245530 | RLSA-2024:5530: python-setuptools security update (Important) | The python-setuptools package provides a collection of enhancements to Python distribution utilities allowing convenient building and distribution of Python packages.
Security Fix(es):
* pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools (CVE-2024-6345)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-08-21 00:00:00+03:00 | 2024-08-21 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:5530', 'https://errata.rockylinux.org/RLSA-2024:5530'] | 5b7251bb44744f9091a36d3c16193652ab2468da064760269bc587d4a2129c6c | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20244617 | RLSA-2024:4617: qt5-qtbase security update (Important) | Qt is a software toolkit for developing applications. The qt5-base packages contain base tools for string, xml, and network handling in Qt.
Security Fix(es):
* qtbase: qtbase: Delay any communication until encrypted() can be responded to (CVE-2024-39936)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-07-26 00:00:00+03:00 | 2024-07-26 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:4617', 'https://errata.rockylinux.org/RLSA-2024:4617'] | eb7083f6823ea3af44225f78544568f759a9cc0402e57dc77be72abb2a3b3d2d | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20244352 | RLSA-2024:4352: kernel-rt security and bug fix update (Important) | The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: tls (CVE-2024-26585,CVE-2024-26584, CVE-2024-26583
* kernel-rt: kernel: PCI interrupt mapping cause oops [rhel-8] (CVE-2021-46909)
* kernel: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry (CVE-2021-47069)
* kernel: hwrng: core - Fix page fault dead lock on mmap-ed hwrng (CVE-2023-52615)
* kernel-rt: kernel: drm/amdgpu: use-after-free vulnerability (CVE-2024-26656)
* kernel: Bluetooth: Avoid potential use-after-free in hci_error_reset CVE-2024-26801)
* kernel: Squashfs: check the inode number is not the invalid value of zero (CVE-2024-26982)
* kernel: netfilter: nf_tables: use timestamp to check for set element timeout (CVE-2024-27397)
* kernel: wifi: mac80211: (CVE-2024-35789, CVE-2024-35838, CVE-2024-35845)
* kernel: wifi: nl80211: reject iftype change with mesh ID change (CVE-2024-27410)
* kernel: perf/core: Bail out early if the request AUX area is out of bound (CVE-2023-52835)
* kernel:TCP-spoofed ghost ACKs and leak initial sequence number (CVE-2023-52881)
* kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack (CVE-2020-26555)
* kernel: ovl: fix leaked dentry (CVE-2021-46972)
* kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios (CVE-2021-47073)
* kernel: mm/damon/vaddr-test: memory leak in damon_do_test_apply_three_regions() (CVE-2023-52560)
* kernel: ppp_async: limit MRU to 64K (CVE-2024-26675)
* kernel: mm/swap: fix race when skipping swapcache (CVE-2024-26759)
* kernel: RDMA/mlx5: Fix fortify source warning while accessing Eth segment (CVE-2024-26907)
* kernel: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault() (CVE-2024-26906)
* kernel: net: ip_tunnel: prevent perpetual headroom growth (CVE-2024-26804)
* kernel: net/usb: kalmia: avoid printing uninitialized value on error path (CVE-2023-52703)
* kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs (CVE-2023-5090)
* kernel: EDAC/thunderx: Incorrect buffer size in drivers/edac/thunderx_edac.c (CVE-2023-52464)
* kernel: ipv6: sr: fix possible use-after-free and null-ptr-deref (CVE-2024-26735)
* kernel: mptcp: fix data re-injection from stale subflow (CVE-2024-26826)
* kernel: net/bnx2x: Prevent access to a freed page in page_pool (CVE-2024-26859)
* kernel: crypto: (CVE-2024-26974, CVE-2023-52813)
* kernel: can: (CVE-2023-52878, CVE-2021-47456)
* kernel: usb: (CVE-2023-52781, CVE-2023-52877)
* kernel: net/mlx5e: fix a potential double-free in fs_any_create_groups (CVE-2023-52667)
* kernel: usbnet: sanity check for maxpacket (CVE-2021-47495)
* kernel: gro: fix ownership transfer (CVE-2024-35890)
* kernel: erspan: make sure erspan_base_hdr is present in skb->head (CVE-2024-35888)
* kernel: tipc: fix kernel warning when sending SYN message (CVE-2023-52700)
* kernel: net/mlx5/mlxsw: (CVE-2024-35960, CVE-2024-36007, CVE-2024-35855)
* kernel: net/mlx5e: (CVE-2024-35959, CVE-2023-52626, CVE-2024-35835)
* kernel: mlxsw: (CVE-2024-35854, CVE-2024-35853, CVE-2024-35852)
* kernel: net: (CVE-2024-35958, CVE-2021-47311, CVE-2021-47236, CVE-2021-47310)
* kernel: i40e: Do not use WQ_MEM_RECLAIM flag for workqueue (CVE-2024-36004)
* kernel: mISDN: fix possible use-after-free in HFC_cleanup() (CVE-2021-47356)
* kernel: udf: Fix NULL pointer dereference in udf_symlink function (CVE-2021-47353)
Bug Fix(es):
* kernel-rt: update RT source tree to the latest Rocky Linux-8.10.z kernel (JIRA:Rocky Linux-40882)
* [rhel8.9][cxgb4]BUG: using smp_processor_id() in preemptible [00000000] code: ethtool/54735 (JIRA:Rocky Linux-8779)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-07-15 00:00:00+03:00 | 2024-07-15 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:4352', 'https://errata.rockylinux.org/RLSA-2024:4352'] | 206fa4f673b536b3c1b3a56afec69aa93ec9c2c5929ea07c417947deee952b9c | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20240806 | RLSA-2024:0806: dotnet7.0 security update (Important) | .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 7.0.116 and .NET Runtime 7.0.16.
Security Fix(es):
* dotnet: Denial of Service in SignalR server (CVE-2024-21386)
* dotnet: Denial of Service in X509Certificate2 (CVE-2024-21404)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-03-12 00:00:00+03:00 | 2024-03-12 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:0806', 'https://errata.rockylinux.org/RLSA-2024:0806'] | 79fdde41934b0cad8d11a4cc9ff70bd68d4711f9fe65ba60e01206cbce38647a | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20233827 | RLSA-2023:3827: libtiff security update (Moderate) | The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.
Security Fix(es):
* libtiff: heap-based buffer overflow in processCropSelections() in tools/tiffcrop.c (CVE-2022-48281)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2023-08-31 00:00:00+03:00 | 2023-08-31 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:3827', 'https://errata.rockylinux.org/RLSA-2023:3827'] | e595d902f89a89d147d2a5d6808f48943e6c8221d09ead080d6a47b5dc694045 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20245101 | RLSA-2024:5101: kernel security update (Important) | The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: powerpc: Fix access beyond end of drmem array (CVE-2023-52451)
* kernel: efivarfs: force RO when remounting if SetVariable is not supported (CVE-2023-52463)
* kernel: tracing: Restructure trace_clock_global() to never block (CVE-2021-46939)
* kernel: ext4: avoid online resizing failures due to oversized flex bg (CVE-2023-52622)
* kernel: net/sched: flower: Fix chain template offload (CVE-2024-26669)
* kernel: stmmac: Clear variable when destroying workqueue (CVE-2024-26802)
* kernel: efi: runtime: Fix potential overflow of soft-reserved region size (CVE-2024-26843)
* kernel: quota: Fix potential NULL pointer dereference (CVE-2024-26878)
* kernel: TIPC message reassembly use-after-free remote code execution vulnerability (CVE-2024-36886)
* kernel: SUNRPC: fix a memleak in gss_import_v2_context (CVE-2023-52653)
* kernel: dmaengine/idxd: hardware erratum allows potential security problem with direct access by untrusted application (CVE-2024-21823)
* kernel: Revert "net/mlx5: Block entering switchdev mode with ns inconsistency" (CVE-2023-52658)
* kernel: ext4: fix corruption during on-line resize (CVE-2024-35807)
* kernel: x86/fpu: Keep xfd_state in sync with MSR_IA32_XFD (CVE-2024-35801)
* kernel: dyndbg: fix old BUG_ON in >control parser (CVE-2024-35947)
* kernel: net/sched: act_skbmod: prevent kernel-infoleak (CVE-2024-35893)
* kernel: x86/mce: Make sure to grab mce_sysfs_mutex in set_bank() (CVE-2024-35876)
* kernel: platform/x86: wmi: Fix opening of char device (CVE-2023-52864)
* kernel: tipc: Change nla_policy for bearer-related names to NLA_NUL_STRING (CVE-2023-52845)
* (CVE-2023-28746)
* (CVE-2023-52847)
* (CVE-2021-47548)
* (CVE-2024-36921)
* (CVE-2024-26921)
* (CVE-2021-47579)
* (CVE-2024-36927)
* (CVE-2024-39276)
* (CVE-2024-33621)
* (CVE-2024-27010)
* (CVE-2024-26960)
* (CVE-2024-38596)
* (CVE-2022-48743)
* (CVE-2024-26733)
* (CVE-2024-26586)
* (CVE-2024-26698)
* (CVE-2023-52619)
Bug Fix(es):
* Rocky Linux8.6 - Spinlock statistics may show negative elapsed time and incorrectly formatted output (JIRA:Rocky Linux-17678)
* [AWS][8.9]There are call traces found when booting debug-kernel for Amazon EC2 r8g.metal-24xl instance (JIRA:Rocky Linux-23841)
* [rhel8] gfs2: Fix glock shrinker (JIRA:Rocky Linux-32941)
* lan78xx: Microchip LAN7800 never comes up after unplug and replug (JIRA:Rocky Linux-33437)
* [Hyper-V][Rocky Linux-8.10.z] Update hv_netvsc driver to TOT (JIRA:Rocky Linux-39074)
* Use-after-free on proc inode-i_sb triggered by fsnotify (JIRA:Rocky Linux-40167)
* blk-cgroup: Properly propagate the iostat update up the hierarchy [rhel-8.10.z] (JIRA:Rocky Linux-40939)
* (JIRA:Rocky Linux-31798)
* (JIRA:Rocky Linux-10263)
* (JIRA:Rocky Linux-40901)
* (JIRA:Rocky Linux-43547)
* (JIRA:Rocky Linux-34876)
Enhancement(s):
* [RFE] Add module parameters 'soft_reboot_cmd' and 'soft_active_on_boot' for customizing softdog configuration (JIRA:Rocky Linux-19723)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-08-21 00:00:00+03:00 | 2024-08-21 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:5101', 'https://errata.rockylinux.org/RLSA-2024:5101'] | 9ccbec538b9ffc4867630bba638632316991ed1895e81b59e59b2f3c6893bb91 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20243059 | RLSA-2024:3059: libtiff security update (Moderate) | The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.
Security Fix(es):
* libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c (CVE-2022-4645)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.10 Release Notes linked from the References section.
Security Fix(es) | Moderate | 2024-06-14 00:00:00+03:00 | 2024-06-14 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:3059', 'https://errata.rockylinux.org/RLSA-2024:3059'] | b1fb4893c8ba8c4e6487a74209000e3e248abb64c41c94be5ffa8ee5ce99183a | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20243344 | RLSA-2024:3344: glibc security update (Important) | The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the name service
cache daemon (nscd) used by multiple programs on the system. Without these
libraries, the Linux system cannot function correctly.
Security Fix(es):
* glibc: stack-based buffer overflow in netgroup cache (CVE-2024-33599)
* glibc: null pointer dereferences after failed netgroup cache insertion
(CVE-2024-33600)
* glibc: netgroup cache may terminate daemon on memory allocation failure
(CVE-2024-33601)
* glibc: netgroup cache assumes NSS callback uses in-buffer strings
(CVE-2024-33602)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Security Fix(es) | Important | 2024-06-14 00:00:00+03:00 | 2024-06-14 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:3344', 'https://errata.rockylinux.org/RLSA-2024:3344'] | a88cdc2f56c7c012ef8d75851b7d004de83c50f7276dbe1584e66619a691d875 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20243341 | RLSA-2024:3341: gdk-pixbuf2 security update (Moderate) | The gdk-pixbuf2 packages provide an image loading library that can be extended
by loadable modules for new image formats. It is used by toolkits such as GTK+
or clutter.
Security Fix(es):
* gdk-pixbuf2: heap memory corruption on gdk-pixbuf (CVE-2022-48622)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-06-14 00:00:00+03:00 | 2024-06-14 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:3341', 'https://errata.rockylinux.org/RLSA-2024:3341'] | 15be86af52338e750f13f0af1c56d3e6bce6c9aca5eca38d8e666af6c54cf330 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20234864 | RLSA-2023:4864: cups security update (Important) | The Common UNIX Printing System (CUPS) provides a portable printing layer for Linux, UNIX, and similar operating systems.
Security Fix(es):
* cups: Information leak through Cups-Get-Document operation (CVE-2023-32360)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2023-08-31 00:00:00+03:00 | 2023-08-31 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:4864', 'https://errata.rockylinux.org/RLSA-2023:4864'] | 2dae0a0ac32cf3ca732920526329286e0e564fafab20558f7acbf7faf2a349f2 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20247262 | RLSA-2024:7262: osbuild-composer security update (Important) | A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.
Security Fix(es):
* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
* encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-09-30 00:00:00+03:00 | 2024-09-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:7262', 'https://errata.rockylinux.org/RLSA-2024:7262'] | 827c3cd8e0d27ad4325801d5c758469f1b4928fd9dd3c0733117949b13f25a50 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20243139 | RLSA-2024:3139: squashfs-tools security update (Moderate) | SquashFS is a highly compressed read-only file system for Linux. These packages contain the utilities for manipulating squashfs file systems.
Security Fix(es):
* squashfs-tools: unvalidated filepaths allow writing outside of destination (CVE-2021-40153)
* squashfs-tools: possible Directory Traversal via symbolic link (CVE-2021-41072)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.10 Release Notes linked from the References section.
Security Fix(es) | Moderate | 2024-06-14 00:00:00+03:00 | 2024-06-14 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:3139', 'https://errata.rockylinux.org/RLSA-2024:3139'] | 379d8771fcfaeaaebfdbeebbbba66c6a3751813d0e21ed7ed1530cb7692e0c66 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20231583 | RLSA-2023:1583: nodejs (Moderate) | Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
The following packages have been upgraded to a later upstream version: nodejs (18.14.2).
Security Fix(es):
* glob-parent: Regular Expression Denial of Service (CVE-2021-35065)
* http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability (CVE-2022-25881)
* Node.js: Permissions policies can be bypassed via process.mainModule (CVE-2023-23918)
* Node.js: Fetch API did not protect against CRLF injection in host headers (CVE-2023-23936)
* Node.js: insecure loading of ICU data through ICU_DATA environment variable (CVE-2023-23920)
* Node.js: Regular Expression Denial of Service in Headers fetch API (CVE-2023-24807)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2023-04-06 00:00:00+03:00 | 2023-04-06 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:1583', 'https://errata.rockylinux.org/RLSA-2023:1583'] | 1eaa75cf8fb9f0ac7e80f1051d25d990c7d5dbd5d34fa0cbe0782ea4a0a3c3ab | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20230096 | RLSA-2023:0096: dbus security update (Moderate) | D-Bus is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility.
Security Fix(es):
* dbus: dbus-daemon crashes when receiving message with incorrectly nested parentheses and curly brackets (CVE-2022-42010)
* dbus: dbus-daemon can be crashed by messages with array length inconsistent with element type (CVE-2022-42011)
* dbus: `_dbus_marshal_byteswap` doesn't process fds in messages with "foreign" endianness correctly (CVE-2022-42012)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2023-01-12 00:00:00+03:00 | 2023-01-12 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:0096', 'https://errata.rockylinux.org/RLSA-2023:0096'] | 15870e3ba8b1c2f51175c2f4378ff3698ddce0fe1dfad4838ea8dbf1b8cad64b | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20242968 | RLSA-2024:2968: fence-agents security and bug fix update (Moderate) | The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.
Security Fix(es):
* urllib3: Request body not stripped after redirect from 303 status changes request method to GET (CVE-2023-45803)
* pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex (CVE-2023-52323)
* jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.10 Release Notes linked from the References section.
Security Fix(es) | Moderate | 2024-06-14 00:00:00+03:00 | 2024-06-14 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:2968', 'https://errata.rockylinux.org/RLSA-2024:2968'] | eed27a46b92d7d72613899e9c38fa0623799217c6ad271921fd5c35c88d94b1f | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20227519 | RLSA-2022:7519: grafana security, bug fix, and enhancement update (Moderate) | Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
The following packages have been upgraded to a later upstream version: grafana (7.5.15). (BZ#2055348)
Security Fix(es):
* sanitize-url: XSS due to improper sanitization in sanitizeUrl function (CVE-2021-23648)
* golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705)
* golang: go/parser: stack exhaustion in all Parse* functions (CVE-2022-1962)
* grafana: Forward OAuth Identity Token can allow users to access some data sources (CVE-2022-21673)
* prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
* grafana: XSS vulnerability in data source handling (CVE-2022-21702)
* grafana: CSRF vulnerability can lead to privilege escalation (CVE-2022-21703)
* grafana: IDOR vulnerability can lead to information disclosure (CVE-2022-21713)
* golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)
* golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)
* golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)
* golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)
* golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)
* golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)
* golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.
Security Fix(es) | Moderate | 2022-11-08 00:00:00+03:00 | 2022-11-08 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:7519', 'https://errata.rockylinux.org/RLSA-2022:7519'] | 26735bba21acba001bbe1e4657873c557eb4a737030ce7a687a07a0cd59e6e6a | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20227469 | RLSA-2022:7469: container-tools (Moderate) | The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
* cri-o: memory exhaustion on the node when access to the kube api (CVE-2022-1708)
* golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)
* runc: incorrect handling of inheritable capabilities (CVE-2022-29162)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.
Security Fix(es) | Moderate | 2022-11-08 00:00:00+03:00 | 2022-11-08 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:7469', 'https://errata.rockylinux.org/RLSA-2022:7469'] | a394e1da45d0ba8e08a1075416349595fa32d84e87cf3fd0ff82d0c0ce84cb01 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20227461 | RLSA-2022:7461: libreoffice security update (Moderate) | LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.
Security Fix(es):
* libreoffice: Incorrect trust validation of signature with ambiguous KeyInfo children (CVE-2021-25636)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.
Security Fix(es) | Moderate | 2022-11-08 00:00:00+03:00 | 2022-11-08 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:7461', 'https://errata.rockylinux.org/RLSA-2022:7461'] | 36d336955718753ea2332aa1262356e54b1895896fce13a417b00bfe23eb047d | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20227458 | RLSA-2022:7458: flatpak-builder security and bug fix update (Moderate) | Flatpak-builder is a tool for building flatpaks from sources.
Security Fix(es):
* flatpak: flatpak-builder --mirror-screenshots-url can access files outside the build directory (CVE-2022-21682)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.
Security Fix(es) | Moderate | 2022-11-08 00:00:00+03:00 | 2022-11-08 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:7458', 'https://errata.rockylinux.org/RLSA-2022:7458'] | 36ed100aed37546c9114fe4eff2eac60d0edb69a20b995030b19d91a0e454492 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246784 | RLSA-2024:6784: ruby (Moderate) | Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.
Security Fix(es):
* rexml: DoS vulnerability in REXML (CVE-2024-39908)
* rexml: rubygem-rexml: DoS when parsing an XML having many specific characters such as whitespace character, >] and ]> (CVE-2024-41123)
* rexml: DoS vulnerability in REXML (CVE-2024-41946)
* rexml: DoS vulnerability in REXML (CVE-2024-43398)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-09-30 00:00:00+03:00 | 2024-09-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6784', 'https://errata.rockylinux.org/RLSA-2024:6784'] | bbc9c49c60b01d414f4df71e00236c68e5cf92b903bde188660533bda1ab080a | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246961 | RLSA-2024:6961: python3.12 security update (Moderate) | Python 3.12 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.12 package provides the "python3.12" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.12-libs package, which should be installed automatically along with python3.12. The remaining parts of the Python standard library are broken out into the python3.12-tkinter and python3.12-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.12-docs package. Packages containing additional libraries for Python are generally named with the "python3.12-" prefix. For the unversioned "python" executable, see manual page "unversioned-python".
Security Fix(es):
* python: incorrect IPv4 and IPv6 private ranges (CVE-2024-4032)
* cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection (CVE-2024-6923)
* python: cpython: Iterating over a malicious ZIP file may lead to Denial of Service (CVE-2024-8088)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-09-30 00:00:00+03:00 | 2024-09-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6961', 'https://errata.rockylinux.org/RLSA-2024:6961'] | 0e8dd80c931165b00d3962974586bf645b144c165f75e9426573b65e60cb9f35 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20241431 | RLSA-2024:1431: ruby (Moderate) | Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.
The following packages have been upgraded to a later upstream version: ruby (3.1). (Rocky Linux-28565)
Security Fix(es):
* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)
* ruby: ReDoS vulnerability in URI (CVE-2023-28755)
* ruby: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755 (CVE-2023-36617)
* ruby: ReDoS vulnerability in Time (CVE-2023-28756)
Bug Fix(es):
* ruby/rubygem-irb: IRB has hard dependency on rubygem-rdoc (Rocky Linux-28569)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-03-27 00:00:00+03:00 | 2024-03-27 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:1431', 'https://errata.rockylinux.org/RLSA-2024:1431'] | 7b7f0b994574916ad549d6a30a0ce565e523eb6a7ad37bb625d99bf4687ae8a7 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246973 | RLSA-2024:6973: dovecot security update (Moderate) | Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.
Security Fix(es):
* dovecot: using a large number of address headers may trigger a denial of service (CVE-2024-23184)
* dovecot: very large headers can cause resource exhaustion when parsing message (CVE-2024-23185)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-09-30 00:00:00+03:00 | 2024-09-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6973', 'https://errata.rockylinux.org/RLSA-2024:6973'] | 61c7a3cf9605beea3d1071fc2db049db0a23fcca9efaa307d9cab83cf3e25db5 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20245258 | RLSA-2024:5258: container-tools (Important) | The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
* golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
* golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)
* golang: net/mail: comments in display names are incorrectly handled (CVE-2024-24784)
* containers/image: digest type does not guarantee valid type (CVE-2024-3727)
* golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789)
* go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104)
* gorilla/schema: Potential memory exhaustion attack due to sparse slice deserialization (CVE-2024-37298)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-08-21 00:00:00+03:00 | 2024-08-21 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:5258', 'https://errata.rockylinux.org/RLSA-2024:5258'] | 8ca6898756524d3eecbea62426be40130caf0460e6665ffb2fc7943a5591e2e8 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20245531 | RLSA-2024:5531: python3.12-setuptools security update (Important) | Setuptools is a collection of enhancements to the Python 3 distutils that allow you to more easily build and distribute Python 3 packages, especially ones that have dependencies on other packages. This package also contains the runtime components of setuptools, necessary to execute the software that requires pkg_resources.
Security Fix(es):
* pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools (CVE-2024-6345)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-08-21 00:00:00+03:00 | 2024-08-21 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:5531', 'https://errata.rockylinux.org/RLSA-2024:5531'] | 3ccf881e794f53d5797cab86c285fa77be7f35ab77f93af5cd49f819567e7280 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20247135 | RLSA-2024:7135: git-lfs security update (Important) | Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.
Security Fix(es):
* encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-09-30 00:00:00+03:00 | 2024-09-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:7135', 'https://errata.rockylinux.org/RLSA-2024:7135'] | a0158b2712859f7670fdcc03be1d46a23ce4d224747bc015d2af9adbef43ed47 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246908 | RLSA-2024:6908: go-toolset (Important) | Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.
Security Fix(es):
* net/http: Denial of service due to improper 100-continue handling in net/http (CVE-2024-24791)
* go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion (CVE-2024-34155)
* encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)
* go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion (CVE-2024-34158)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-09-30 00:00:00+03:00 | 2024-09-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6908', 'https://errata.rockylinux.org/RLSA-2024:6908'] | 95930e3957330d061a88cbc54c508c3bf5d888312ed9b44a46726593ebcdd4a6 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20245193 | RLSA-2024:5193: httpd (Important) | The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.
Security Fix(es):
* httpd: Security issues via?backend applications whose response headers are malicious or exploitable (CVE-2024-38476)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-08-21 00:00:00+03:00 | 2024-08-21 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:5193', 'https://errata.rockylinux.org/RLSA-2024:5193'] | 537c9962eec82161d3231b1901a89a6f65972a4cdffaaeeaf102716a7dd3aa39 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20227190 | RLSA-2022:7190: thunderbird security update (Important) | Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 102.4.0.
Security Fix(es):
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack by malicious server administrators (CVE-2022-39249)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to a device verification attack (CVE-2022-39250)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack (CVE-2022-39251)
* Mozilla: Same-origin policy violation could have leaked cross-origin URLs (CVE-2022-42927)
* Mozilla: Memory Corruption in JS Engine (CVE-2022-42928)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to a data corruption issue (CVE-2022-39236)
* Mozilla: Denial of Service via window.print (CVE-2022-42929)
* Mozilla: Memory safety bugs fixed in Firefox ESR 102.4 and Thunderbird 102.4 (CVE-2022-42932)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-10-25 00:00:00+03:00 | 2022-10-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:7190', 'https://errata.rockylinux.org/RLSA-2022:7190'] | 1b5721b0893de10df6c8fa5a6cfec8e085947330f5ec26de594d35d1d463c11e | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246975 | RLSA-2024:6975: python3 security update (Moderate) | Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.
Security Fix(es):
* python: incorrect IPv4 and IPv6 private ranges (CVE-2024-4032)
* cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection (CVE-2024-6923)
* python: cpython: tarfile: ReDos via excessive backtracking while parsing header values (CVE-2024-6232)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-09-30 00:00:00+03:00 | 2024-09-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6975', 'https://errata.rockylinux.org/RLSA-2024:6975'] | c9b133960f40ed068ec812cc42ae47f2e41281b5215cfe702e819e8d43f397fb | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246670 | RLSA-2024:6670: pcs security update (Moderate) | The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.
Security Fix(es):
* rexml: rubygem-rexml: DoS when parsing an XML having many specific characters such as whitespace character, >] and ]> (CVE-2024-41123)
* rexml: DoS vulnerability in REXML (CVE-2024-41946)
* rexml: DoS vulnerability in REXML (CVE-2024-43398)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-09-17 00:00:00+03:00 | 2024-09-17 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6670', 'https://errata.rockylinux.org/RLSA-2024:6670'] | 7312e8291721b806548ab9f95e57893e4a616d403a229aff1b29d71dc98aea4f | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20245941 | RLSA-2024:5941: libvpx security update (Moderate) | The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.
Security Fix(es):
* libvpx: Heap buffer overflow related to VP9 encoding (CVE-2023-6349)
* libvpx: Integer overflow in vpx_img_alloc() (CVE-2024-5197)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-09-17 00:00:00+03:00 | 2024-09-17 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:5941', 'https://errata.rockylinux.org/RLSA-2024:5941'] | 44bf0f16f2cbdddbd91770b58fdc7938e583174c77b6c48ba659a72ecbfc3262 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20226708 | RLSA-2022:6708: thunderbird security update (Important) | Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 102.3.0.
Security Fix(es):
* Mozilla: Leaking of sensitive information when composing a response to an HTML email with a META refresh tag (CVE-2022-3033)
* Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959)
* Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960)
* Mozilla: Memory safety bugs fixed in Firefox 105 and Firefox ESR 102.3 (CVE-2022-40962)
* Mozilla: Remote content specified in an HTML document that was nested inside an iframe's srcdoc attribute was not blocked (CVE-2022-3032)
* Mozilla: An iframe element in an HTML email could trigger a network request (CVE-2022-3034)
* Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack (CVE-2022-36059)
* Mozilla: Bypassing Secure Context restriction for cookies with __Host and __Secure prefix (CVE-2022-40958)
* Mozilla: Content-Security-Policy base-uri bypass (CVE-2022-40956)
* Mozilla: Incoherent instruction cache when building WASM on ARM64 (CVE-2022-40957)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-09-26 00:00:00+03:00 | 2022-09-26 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:6708', 'https://errata.rockylinux.org/RLSA-2022:6708'] | f91e3b17299774aa9eb9e5796aaa04743cbf50c1759914916c8a799c85249e9b | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20247868 | RLSA-2024:7868: .NET 8.0 security update (Important) | .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.110 and .NET Runtime 8.0.10.
Security Fix(es):
* dotnet: kestrel: closing an HTTP/3 stream can cause a race condition and lead to remote code execution (CVE-2024-38229)
* dotnet: Multiple .NET components susceptible to hash flooding (CVE-2024-43483)
* dotnet: System.IO.Packaging - Multiple DoS vectors in use of SortedList (CVE-2024-43484)
* dotnet: Denial of Service in System.Text.Json (CVE-2024-43485)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Security Fix(es):
* dotnet: System.IO.Packaging - Multiple DoS vectors in use of SortedList (CVE-2024-43484)
* dotnet: Multiple .NET components susceptible to hash flooding (CVE-2024-43483)
* dotnet: Denial of Service in System.Text.Json (CVE-2024-43485)
* dotnet: kestrel: closing an HTTP/3 stream can cause a race condition and lead to remote code execution (CVE-2024-38229)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-10-25 00:00:00+03:00 | 2024-10-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:7868', 'https://errata.rockylinux.org/RLSA-2024:7868'] | a47405119ef106527600232dadfcd5c8dae017bd4942d012a0cdd3959d28dda8 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20247851 | RLSA-2024:7851: .NET 6.0 security update (Important) | .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 6.0.135 and .NET Runtime 6.0.35.
Security Fix(es):
* dotnet: System.IO.Packaging - Multiple DoS vectors in use of SortedList (CVE-2024-43484)
* dotnet: Multiple .NET components susceptible to hash flooding (CVE-2024-43483)
* dotnet: Denial of Service in System.Text.Json (CVE-2024-43485)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Security Fix(es):
* dotnet: System.IO.Packaging - Multiple DoS vectors in use of SortedList (CVE-2024-43484)
* dotnet: Multiple .NET components susceptible to hash flooding (CVE-2024-43483)
* dotnet: Denial of Service in System.Text.Json (CVE-2024-43485)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-10-25 00:00:00+03:00 | 2024-10-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:7851', 'https://errata.rockylinux.org/RLSA-2024:7851'] | 24208220f5681f9ccab048ada78a9dfff0b51914ada05a7eae46166217c913dd | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20247463 | RLSA-2024:7463: cups-filters security update (Important) | The cups-filters package contains back ends, filters, and other software that was once part of the core Common UNIX Printing System (CUPS) distribution but is now maintained independently.
Security Fix(es):
* cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source ()
* cups-filters: libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes (CVE-2024-47076)
* cups: libppd: remote command injection via attacker controlled data in PPD file ()
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-10-25 00:00:00+03:00 | 2024-10-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:7463', 'https://errata.rockylinux.org/RLSA-2024:7463'] | 72efd7811ccf90c1a26cc54cb3137aa539d6fb6bc1e972eb929798d98dcebe9d | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20244620 | RLSA-2024:4620: libndp security update (Important) | Libndp is a library (used by NetworkManager) that provides a wrapper for the IPv6 Neighbor Discovery Protocol. It also provides a tool named ndptool for sending and receiving NDP messages.
Security Fix(es):
* libndp: buffer overflow in route information length field (CVE-2024-5564)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-07-26 00:00:00+03:00 | 2024-07-26 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:4620', 'https://errata.rockylinux.org/RLSA-2024:4620'] | 3f6e5c9230f5fbcab7cefdcb6544cea25b5284e4c2efd062f0dae73732ebe3f4 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20241494 | RLSA-2024:1494: thunderbird security update (Moderate) | Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 115.9.0.
Security Fix(es):
* nss: timing attack against RSA decryption (CVE-2023-5388)
* Mozilla: Crash in NSS TLS method (CVE-2024-0743)
* Mozilla: Leaking of encrypted email subjects to other conversations (CVE-2024-1936)
* Mozilla: JIT code failed to save return registers on Armv7-A (CVE-2024-2607)
* Mozilla: Integer overflow could have led to out of bounds write
(CVE-2024-2608)
* Mozilla: Improper handling of html and body tags enabled CSP nonce leakage
(CVE-2024-2610)
* Mozilla: Clickjacking vulnerability could have led to a user accidentally
granting permissions (CVE-2024-2611)
* Mozilla: Self referencing object could have potentially led to a
use-after-free (CVE-2024-2612)
* Mozilla: Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9, and
Thunderbird 115.9 (CVE-2024-2614)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-03-27 00:00:00+03:00 | 2024-03-27 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:1494', 'https://errata.rockylinux.org/RLSA-2024:1494'] | a8cddc28fa6d7d8af9871dc9c34c09260cc0e007f16fa9a560cba06414df762a | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20226437 | RLSA-2022:6437: kernel-rt security and bug fix update (Moderate) | The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* Incomplete cleanup of multi-core shared buffers (aka SBDR) (CVE-2022-21123)
* Incomplete cleanup of microarchitectural fill buffers (aka SBDS) (CVE-2022-21125)
* Incomplete cleanup in specific special register write operations (aka DRPW) (CVE-2022-21166)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* The latest Rocky Linux 8.6.z3 kernel changes need to be merged into the RT source tree to keep source parity between the two kernels. (BZ#2111112)
Security Fix(es) | Moderate | 2022-09-13 00:00:00+03:00 | 2022-09-13 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:6437', 'https://errata.rockylinux.org/RLSA-2022:6437'] | 8c66110ee830b2bee142f8114d21ce7ae85dda1705e67a5bb271391130beade8 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20247700 | RLSA-2024:7700: firefox security update (Important) | Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Security Fix(es):
* firefox: 115.16/128.3 ESR ()
* firefox: thunderbird: Specially crafted WebTransport requests could lead to denial of service (CVE-2024-9399)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131 and Thunderbird 131 (CVE-2024-9403)
* firefox: thunderbird: Potential directory upload bypass via clickjacking (CVE-2024-9397)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 (CVE-2024-9401)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 (CVE-2024-9402)
* firefox: thunderbird: External protocol handlers could be enumerated via popups (CVE-2024-9398)
* firefox: thunderbird: Potential memory corruption during JIT compilation (CVE-2024-9400)
* firefox: thunderbird: Potential memory corruption may occur when cloning certain objects (CVE-2024-9396)
* firefox: thunderbird: Cross-origin access to PDF contents through multipart responses (CVE-2024-9393)
* firefox: thunderbird: Cross-origin access to JSON contents through multipart responses (CVE-2024-9394)
* firefox: thunderbird: Compromised content process can bypass site isolation (CVE-2024-9392)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-10-25 00:00:00+03:00 | 2024-10-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:7700', 'https://errata.rockylinux.org/RLSA-2024:7700'] | f0b133cc65cd2dc17dba2a8ec742e35da6a43f934a8ea6ab9fb4f6f3c9d32882 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20241514 | RLSA-2024:1514: libreoffice security fix update (Important) | LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.
Security Fix(es):
* libreoffice: Improper Input Validation leading to arbitrary gstreamer plugin execution (CVE-2023-6185)
* libreoffice: Insufficient macro permission validation leading to macro execution (CVE-2023-6186)
Security Fix(es) | Important | 2024-03-27 00:00:00+03:00 | 2024-03-27 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:1514', 'https://errata.rockylinux.org/RLSA-2024:1514'] | b428f5a23fadc43e82899d1c3c1ee7eecc30366d917b77ec7864c37a6df6f04c | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20226206 | RLSA-2022:6206: systemd security update (Important) | The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelism capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups. In addition, it supports snapshotting and restoring of the system state, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. It can also work as a drop-in replacement for sysvinit.
Security Fix(es):
* systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c (CVE-2022-2526)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-08-29 00:00:00+03:00 | 2022-08-29 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:6206', 'https://errata.rockylinux.org/RLSA-2022:6206'] | 907bc8f9369b23c6596373ae4adaef4b356d90eca3f2162ab737e7c4f16d7936 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20240609 | RLSA-2024:0609: thunderbird security update (Important) | Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 115.7.0.
Security Fix(es):
* Mozilla: Out of bounds write in ANGLE (CVE-2024-0741)
* Mozilla: Failure to update user input timestamp (CVE-2024-0742)
* Mozilla: Crash when listing printers on Linux (CVE-2024-0746)
* Mozilla: Bypass of Content Security Policy when directive unsafe-inline was set (CVE-2024-0747)
* Mozilla: Phishing site popup could show local origin in address bar (CVE-2024-0749)
* Mozilla: Potential permissions request bypass via clickjacking (CVE-2024-0750)
* Mozilla: Privilege escalation through devtools (CVE-2024-0751)
* Mozilla: HSTS policy on subdomain could bypass policy of upper domain (CVE-2024-0753)
* Mozilla: Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7 (CVE-2024-0755)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-02-12 00:00:00+03:00 | 2024-02-12 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:0609', 'https://errata.rockylinux.org/RLSA-2024:0609'] | 37db2d2be29433e76e11ca64e614c5b89ba2f888c099df875c3754dcf0f8137b | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20226175 | RLSA-2022:6175: firefox security update (Important) | Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 91.13.0 ESR.
Security Fix(es):
* Mozilla: Address bar spoofing via XSLT error handling (CVE-2022-38472)
* Mozilla: Cross-origin XSLT Documents would have inherited the parent's permissions (CVE-2022-38473)
* Mozilla: Memory safety bugs fixed in Firefox 104 and Firefox ESR 102.2 (CVE-2022-38477)
* Mozilla: Memory safety bugs fixed in Firefox 104, Firefox ESR 102.2, and Firefox ESR 91.13 (CVE-2022-38478)
* Mozilla: Data race and potential use-after-free in PK11_ChangePW (CVE-2022-38476)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-08-24 00:00:00+03:00 | 2022-08-24 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:6175', 'https://errata.rockylinux.org/RLSA-2022:6175'] | e2277032e49ad817a6d4c31538df5cc4be9acb6e36abd562eb834c181ba87c4d | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20226164 | RLSA-2022:6164: thunderbird security update (Important) | Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 91.13.0.
Security Fix(es):
* Mozilla: Address bar spoofing via XSLT error handling (CVE-2022-38472)
* Mozilla: Cross-origin XSLT Documents would have inherited the parent's permissions (CVE-2022-38473)
* Mozilla: Memory safety bugs fixed in Firefox 104 and Firefox ESR 102.2 (CVE-2022-38477)
* Mozilla: Memory safety bugs fixed in Firefox 104, Firefox ESR 102.2, and Firefox ESR 91.13 (CVE-2022-38478)
* Mozilla: Data race and potential use-after-free in PK11_ChangePW (CVE-2022-38476)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-08-24 00:00:00+03:00 | 2022-08-24 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:6164', 'https://errata.rockylinux.org/RLSA-2022:6164'] | 49d019c12441d6a8eacab8a5079d63ed4c0b7785e0bbe3c6a7a23de32f109b11 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225823 | RLSA-2022:5823: 389-ds (Moderate) | 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.
Security Fix(es):
* 389-ds-base: sending crafted message could result in DoS (CVE-2022-0918)
* 389-ds-base: expired password was still allowed to access the database (CVE-2022-0996)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2022-08-02 00:00:00+03:00 | 2022-08-02 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5823', 'https://errata.rockylinux.org/RLSA-2022:5823'] | af9a323fb20e4c6bf4a80679d15b6a4ee11d3b371def121040c82a14ba215bb4 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225821 | RLSA-2022:5821: virt (Moderate) | Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:Rocky Linux module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.
Security Fix(es):
* QEMU: QXL: integer overflow in cursor_alloc() can lead to heap buffer overflow (CVE-2021-4206)
* QEMU: QXL: double fetch in qxl_cursor() can lead to heap buffer overflow (CVE-2021-4207)
* QEMU: virtio-net: map leaking on error during receive (CVE-2022-26353)
* QEMU: vhost-vsock: missing virtqueue detach on error can lead to memory leak (CVE-2022-26354)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Rocky Linux 9.0 guest with vsock device migration failed from Rocky Linux 9.0 > Rocky Linux 8.6 (BZ#2071103)
* Fail to rebuild the reference count tables of qcow2 image on host block devices (e.g. LVs) (BZ#2072242)
* Remove upstream-only devices from the qemu-kvm binary (BZ#2077928)
* When doing a cpu-baseline between skylake and cascadelake, cascadelake is selected as baseline. (BZ#2084030)
* Virt-v2v can't convert Rocky Linux8.6 guest from VMware on Rocky Linux8.6 (BZ#2093415)
Enhancement(s):
* Allow memory prealloc from multiple threads (BZ#2075569)
Security Fix(es) | Moderate | 2022-08-02 00:00:00+03:00 | 2022-08-02 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5821', 'https://errata.rockylinux.org/RLSA-2022:5821'] | 225b273ada38964dbd9148b486de322002f3234a11b70d9ae17b9f653fb6eb36 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20237202 | RLSA-2023:7202: container-tools (Moderate) | The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
* golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* could not find symbol `criu_set_lsm_mount_context` in `libcriu.so` (BZ#2242871)
Security Fix(es) | Moderate | 2023-11-28 00:00:00+03:00 | 2023-11-28 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:7202', 'https://errata.rockylinux.org/RLSA-2023:7202'] | 637d7d0baa19c7f808fc75e00c5c389bc2250da724a4e80585e6493a08853f68 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225819 | RLSA-2022:5819: kernel security and bug fix update (Important) | The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak (CVE-2022-1012)
* kernel: a use-after-free write in the netfilter subsystem can lead to privilege escalation to root (CVE-2022-32250)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Softirq hrtimers are being placed on the per-CPU softirq clocks on isolcpu’s. (BZ#2090484)
* enable/disable multiqueues repeatedly while ping local host, guest kernel panic (BZ#2093416)
* Backport kernel audit enhancements and fixes from v5.13-rc1 to v5.16-rc6 (BZ#2095434)
* blk_update_request: I/O error, dev nvme0n3, during xfs creation (BZ#2100150)
* SCSI updates for Rocky Linux 8.7 (BZ#2100254)
* Kernel bug on mm/slub.c:314 (BZ#2102251)
* Implement new tc action for check_pkt_len (BZ#2102333)
* too long timeout value with TIME_WAIT status of conntrack entry (BZ#2104002)
* Connectx6-DX, mlx5 , backport 087032ee7021 ("net/mlx5e: TC, Fix ct_clear overwriting ct action metadata") (BZ#2104012)
* mlx5: Software steering memory allocation failure, netperf TCP_CRR with ct(). (BZ#2104013)
* tcp: request_sock leak in Calico OCP (BZ#2104670)
Security Fix(es) | Important | 2022-08-02 00:00:00+03:00 | 2022-08-02 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5819', 'https://errata.rockylinux.org/RLSA-2022:5819'] | 2671d9d89b25b4ac7af2ca15b9495d9cde4e3e7a5c97893bfb57845f9c39fe46 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225775 | RLSA-2022:5775: go-toolset (Important) | Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.
Security Fix(es):
* golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)
* golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705)
* golang: go/parser: stack exhaustion in all Parse* functions (CVE-2022-1962)
* golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)
* golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)
* golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)
* golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)
* golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)
* golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Clean up dist-git patches (BZ#2110942)
* Update Go to version 1.17.12 (BZ#2110943)
Security Fix(es) | Important | 2022-08-01 00:00:00+03:00 | 2022-08-01 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5775', 'https://errata.rockylinux.org/RLSA-2022:5775'] | 46428901c137a7d52054d0bb29cb7bb66d8652bbe08bd6b9f4a8795e50317f8c | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225726 | RLSA-2022:5726: java-17-openjdk security, bug fix, and enhancement update (Important) | The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit.
The following packages have been upgraded to a later upstream version: java-17-openjdk (17.0.4.0.8). (BZ#2084650)
Security Fix(es):
* OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) (CVE-2022-34169)
* OpenJDK: class compilation issue (Hotspot, 8281859) (CVE-2022-21540)
* OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866) (CVE-2022-21541)
* OpenJDK: random exponentials issue (Libraries, 8283875) (CVE-2022-21549)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Previous Rocky Enterprise Software Foundation builds of OpenJDK 17 altered the arguments passed to sun.security.pkcs11.wrapper.PKCS11.getInstance() in order to facilitate FIPS support. This build adds an additional form of the method, retaining the original arguments, so that applications which depend on this internal method continue to function with Rocky Enterprise Software Foundation builds of OpenJDK. (BZ#2099913)
* With previous Rocky Enterprise Software Foundation builds of OpenJDK 17, Mac key generation and import would fail due to the lack of the CKA_SIGN attribute on the key. This attribute is now added as part of the NSS FIPS configuration. (BZ#2108190)
* With the release of Rocky Linux 8.6, a change was made so that disabling OpenJDK FIPS mode required the use of both the -Djava.security.disableSystemPropertiesFile=true and -Dcom.redhat.fips=false options, with the intention that FIPS mode could be controlled independently of system security properties. This change has now been reverted and only -Djava.security.disableSystemPropertiesFile=true is required to disable FIPS mode, as in Rocky Linux 8.4. (BZ#2108206)
* Previous Rocky Enterprise Software Foundation builds of OpenJDK 17 running in FIPS mode with a SecurityManager would fail due to a lack of module access permissions. This has now been corrected. (BZ#2108209)
Security Fix(es) | Important | 2022-07-26 00:00:00+03:00 | 2022-07-26 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5726', 'https://errata.rockylinux.org/RLSA-2022:5726'] | 4051c032ab14a8aa212275c19f1e0b16dde10935cbeab481a0d595f1219c6edc | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20244451 | RLSA-2024:4451: dotnet8.0 security update (Important) | .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.107 and Runtime 8.0.7.
Security Fix(es):
* dotnet: DoS in System.Text.Json (CVE-2024-30105)
* dotnet: DoS in ASP.NET Core 8 (CVE-2024-35264)
* dotnet: DoS when parsing X.509 Content and ObjectIdentifiers (CVE-2024-38095)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-07-15 00:00:00+03:00 | 2024-07-15 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:4451', 'https://errata.rockylinux.org/RLSA-2024:4451'] | e773383ae8bba2aeea21c015993090a0d6564f9fc0b9d46046b85005a9703356 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20244227 | RLSA-2024:4227: python-pillow security update (Moderate) | The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.
Security Fix(es):
* python-pillow: buffer overflow in _imagingcms.c (CVE-2024-28219)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-07-15 00:00:00+03:00 | 2024-07-15 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:4227', 'https://errata.rockylinux.org/RLSA-2024:4227'] | edbe7a51cbfa2e0ab36dd0587757a66b0df8840d127f21a44183eec89d483bb5 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20235312 | RLSA-2023:5312: open-vm-tools security update (Important) | The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines.
Security Fix(es):
* open-vm-tools: SAML token signature bypass (CVE-2023-20900)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2023-09-26 00:00:00+03:00 | 2023-09-26 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:5312', 'https://errata.rockylinux.org/RLSA-2023:5312'] | cb22954cb49d4a29a9d4e2c0018f4a3666a9b57e0b67baea0356f0c2591ac48e | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225696 | RLSA-2022:5696: java-1.8.0-openjdk security, bug fix, and enhancement update (Important) | The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.
The following packages have been upgraded to a later upstream version: java-1.8.0-openjdk (1.8.0.342.b07). (BZ#2084648)
Security Fix(es):
* OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) (CVE-2022-34169)
* OpenJDK: class compilation issue (Hotspot, 8281859) (CVE-2022-21540)
* OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866) (CVE-2022-21541)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* rh1991003 patch breaks sun.security.pkcs11.wrapper.PKCS11.getInstance() [Rocky Linux-8, openjdk-8] (BZ#2099911)
* Revert to disabling system security properties and FIPS mode support together [Rocky Linux-8, openjdk-8] (BZ#2108564)
* SecretKey generate/import operations don't add the CKA_SIGN attribute in FIPS mode [Rocky Linux-8, openjdk-8] (BZ#2108566)
Security Fix(es) | Important | 2022-07-25 00:00:00+03:00 | 2022-07-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5696', 'https://errata.rockylinux.org/RLSA-2022:5696'] | 7aeb7c397d0def914b607c660b2eb2740adf4095a08015953026659663bdf66e | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246684 | RLSA-2024:6684: thunderbird security update (Important) | Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
* thunderbird: 115.15/128.2 ()
* mozilla: Type confusion when looking up a property name in a "with" block (CVE-2024-8381)
* mozilla: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran (CVE-2024-8382)
* mozilla: Garbage collection could mis-color cross-compartment objects in OOM conditions (CVE-2024-8384)
* mozilla: WASM type confusion involving ArrayTypes (CVE-2024-8385)
* mozilla: SelectElements could be shown over another site if popups are allowed (CVE-2024-8386)
* mozilla: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2 (CVE-2024-8387)
* thunderbird: Crash when aborting verification of OTR chat (CVE-2024-8394)
* mozilla: Type Confusion in Async Generators in Javascript Engine (CVE-2024-7652)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-09-17 00:00:00+03:00 | 2024-09-17 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6684', 'https://errata.rockylinux.org/RLSA-2024:6684'] | 43e96e7d76d06fc621f23e137314b3f3a335cccb3fcbe2e44b0a0007d2f90f34 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20246000 | RLSA-2024:6000: postgresql (Important) | PostgreSQL is an advanced object-relational database management system (DBMS).
Security Fix(es):
* postgresql: PostgreSQL relation replacement during pg_dump executes arbitrary SQL (CVE-2024-7348)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-09-17 00:00:00+03:00 | 2024-09-17 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:6000', 'https://errata.rockylinux.org/RLSA-2024:6000'] | 45803168b261a85ff57368d4104cc16bdf2e494f12d9609c201eda70a93a0d4a | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20244231 | RLSA-2024:4231: python-jinja2 security update (Moderate) | The python-jinja2 package contains Jinja2, a template engine written in pure Python. Jinja2 provides a Django inspired non-XML syntax but supports inline expressions and an optional sandboxed environment.
Security Fix(es):
* jinja2: accepts keys containing non-attribute characters (CVE-2024-34064)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-07-15 00:00:00+03:00 | 2024-07-15 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:4231', 'https://errata.rockylinux.org/RLSA-2024:4231'] | 1f7aaccd728936f86dfdeae069d93a54d84a032f02c085d17effc07c13fe1681 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20243618 | RLSA-2024:3618: kernel update (Moderate) | The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: Marvin vulnerability side-channel leakage in the RSA decryption
operation (CVE-2023-6240)
* kernel: Information disclosure in vhost/vhost.c:vhost_new_msg()
(CVE-2024-0340)
* kernel: untrusted VMM can trigger int80 syscall handling (CVE-2024-25744)
* kernel: i2c: i801: Fix block process call transactions (CVE-2024-26593)
* kernel: pvrusb2: fix use after free on context disconnection (CVE-2023-52445)
* kernel: x86/fpu: Stop relying on userspace for info to fault in xsave buffer
that cause loop forever (CVE-2024-26603)
* kernel: use after free in i2c (CVE-2019-25162)
* kernel: i2c: validate user data in compat ioctl (CVE-2021-46934)
* kernel: media: dvbdev: Fix memory leak in dvb_media_device_free()
(CVE-2020-36777)
* kernel: usb: hub: Guard against accesses to uninitialized BOS descriptors
(CVE-2023-52477)
* kernel: mtd: require write permissions for locking and badblock ioctls
(CVE-2021-47055)
* kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump
(CVE-2024-26615)
* kernel: vt: fix memory overlapping when deleting chars in the buffer
(CVE-2022-48627)
* kernel: Integer Overflow in raid5_cache_count (CVE-2024-23307)
* kernel: media: uvcvideo: out-of-bounds read in uvc_query_v4l2_menu()
(CVE-2023-52565)
* kernel: net: bridge: data races indata-races in br_handle_frame_finish()
(CVE-2023-52578)
* kernel: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
(CVE-2023-52528)
* kernel: platform/x86: think-lmi: Fix reference leak (CVE-2023-52520)
* kernel: RDMA/siw: Fix connection failure handling (CVE-2023-52513)
* kernel: pid: take a reference when initializing `cad_pid` (CVE-2021-47118)
* kernel: net/sched: act_ct: fix skb leak and crash on ooo frags
(CVE-2023-52610)
* kernel: netfilter: nf_tables: mark set as dead when unbinding anonymous set
with timeout (CVE-2024-26643)
* kernel: netfilter: nf_tables: disallow anonymous set with timeout flag
(CVE-2024-26642)
* kernel: i2c: i801: Don't generate an interrupt on bus reset
(CVE-2021-47153)
* kernel: xhci: handle isoc Babble and Buffer Overrun events properly
(CVE-2024-26659)
* kernel: hwmon: (coretemp) Fix out-of-bounds memory access (CVE-2024-26664)
* kernel: wifi: mac80211: fix race condition on enabling fast-xmit
(CVE-2024-26779)
* kernel: RDMA/srpt: Support specifying the srpt_service_guid parameter
(CVE-2024-26744)
* kernel: RDMA/qedr: Fix qedr_create_user_qp error flow (CVE-2024-26743)
* kernel: tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc
(CVE-2021-47185)
* kernel: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
(CVE-2024-26901)
* kernel: RDMA/srpt: Do not register event handler until srpt device is fully
setup (CVE-2024-26872)
* kernel: usb: ulpi: Fix debugfs directory leak (CVE-2024-26919)
* kernel: usb: xhci: Add error handling in xhci_map_urb_for_dma (CVE-2024-26964)
* kernel: USB: core: Fix deadlock in usb_deauthorize_interface()
(CVE-2024-26934)
* kernel: USB: core: Fix deadlock in port "disable" sysfs attribute
(CVE-2024-26933)
* kernel: fs: sysfs: Fix reference leak in sysfs_break_active_protection()
(CVE-2024-26993)
* kernel: fat: fix uninitialized field in nostale filehandles (CVE-2024-26973)
* kernel: USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command
(CVE-2024-27059)
* kernel: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send (CVE-2021-47013)
* kernel: net: usb: fix memory leak in smsc75xx_bind (CVE-2021-47171)
* kernel: powerpc/pseries: Fix potential memleak in papr_get_attr() (CVE-2022-48669)
* kernel: uio: Fix use-after-free in uio_open (CVE-2023-52439)
* kernel: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus() (CVE-2023-52594)
* kernel: wifi: rt2x00: restart beacon queue when hardware reset (CVE-2023-52595)
Security Fix(es) | Moderate | 2024-06-14 00:00:00+03:00 | 2024-06-14 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:3618', 'https://errata.rockylinux.org/RLSA-2024:3618'] | 9c77cacbbca06810ee4d58964c07fad6fe2fb8fc9b56df0f095230f8baff5255 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20248038 | RLSA-2024:8038: container-tools (Important) | The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
* golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
* go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion (CVE-2024-34155)
* encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)
* go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion (CVE-2024-34158)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-10-25 00:00:00+03:00 | 2024-10-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:8038', 'https://errata.rockylinux.org/RLSA-2024:8038'] | 32616d4d303beff0fb014742e91f262ae1f397b8d5b2f5bdfb57d4d6a6679a88 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20243258 | RLSA-2024:3258: xorg-x11-server security update (Moderate) | X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.
Security Fix(es):
* xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents (CVE-2024-31080)
* xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice (CVE-2024-31081)
* xorg-x11-server: Use-after-free in ProcRenderAddGlyphs (CVE-2024-31083)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-06-14 00:00:00+03:00 | 2024-06-14 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:3258', 'https://errata.rockylinux.org/RLSA-2024:3258'] | e9be4c9679eab2c85ba55633d8d937bb67e05dafd0d03f35e4715cd03473a4c8 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20235184 | RLSA-2023:5184: firefox security update (Important) | Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 102.15.1 ESR.
Security Fix(es):
* libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2023-09-19 00:00:00+03:00 | 2023-09-19 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:5184', 'https://errata.rockylinux.org/RLSA-2023:5184'] | 7a981bb2fb0f1457b645a480c816d378370c625babb7a40393f9e59c2fe28652 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20247699 | RLSA-2024:7699: thunderbird security update (Important) | Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
* thunderbird: 115.16/128.3 ()
* firefox: thunderbird: Specially crafted WebTransport requests could lead to denial of service (CVE-2024-9399)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131 and Thunderbird 131 (CVE-2024-9403)
* firefox: thunderbird: Potential directory upload bypass via clickjacking (CVE-2024-9397)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 (CVE-2024-9401)
* firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 (CVE-2024-9402)
* firefox: thunderbird: External protocol handlers could be enumerated via popups (CVE-2024-9398)
* firefox: thunderbird: Potential memory corruption during JIT compilation (CVE-2024-9400)
* firefox: thunderbird: Potential memory corruption may occur when cloning certain objects (CVE-2024-9396)
* firefox: thunderbird: Cross-origin access to PDF contents through multipart responses (CVE-2024-9393)
* firefox: thunderbird: Cross-origin access to JSON contents through multipart responses (CVE-2024-9394)
* firefox: thunderbird: Compromised content process can bypass site isolation (CVE-2024-9392)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2024-10-25 00:00:00+03:00 | 2024-10-25 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:7699', 'https://errata.rockylinux.org/RLSA-2024:7699'] | 33c7d44453dde70f401f328db970d37ec0c72a0c4497a7164cc91a2f8f3a6a0e | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20240105 | RLSA-2024:0105: nss security update (Moderate) | Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.
Security Fix(es):
* nss: timing attack against RSA decryption (CVE-2023-5388)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-01-12 00:00:00+03:00 | 2024-01-12 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:0105', 'https://errata.rockylinux.org/RLSA-2024:0105'] | d981f1825969b7aaffd6cf463c8ccd6ab7f05ae38ccd4080228f67419427f189 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20240155 | RLSA-2024:0155: gnutls security update (Moderate) | The gnutls packages provide the GNU Transport Layer Security (GnuTLS) library, which implements cryptographic algorithms and protocols such as SSL, TLS, and DTLS.
Security Fix(es):
* gnutls: timing side-channel in the RSA-PSK authentication (CVE-2023-5981)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2024-01-12 00:00:00+03:00 | 2024-01-12 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:0155', 'https://errata.rockylinux.org/RLSA-2024:0155'] | effe9c481488c5991da09bb8184d8112b27fc1ed0ef975bba7af182db9edbfe1 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225683 | RLSA-2022:5683: java-11-openjdk security, bug fix, and enhancement update (Important) | The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.
The following packages have been upgraded to a later upstream version: java-11-openjdk (11.0.16.0.8). (BZ#2084649)
Security Fix(es):
* OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) (CVE-2022-34169)
* OpenJDK: class compilation issue (Hotspot, 8281859) (CVE-2022-21540)
* OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866) (CVE-2022-21541)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* rh1991003 patch breaks sun.security.pkcs11.wrapper.PKCS11.getInstance() [Rocky Linux-8, openjdk-11] (BZ#2099917)
* Revert to disabling system security properties and FIPS mode support together [Rocky Linux-8, openjdk-11] (BZ#2108248)
* SecretKey generate/import operations don't add the CKA_SIGN attribute in FIPS mode [Rocky Linux-8, openjdk-11] (BZ#2108251)
Security Fix(es) | Important | 2022-07-21 00:00:00+03:00 | 2022-07-21 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5683', 'https://errata.rockylinux.org/RLSA-2022:5683'] | 994270e625266cc59584e0aa132e5dd4476395d8eda6bfc497d275ef00b2e4b4 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225565 | RLSA-2022:5565: kernel-rt security and bug fix update (Important) | The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: race condition in perf_event_open leads to privilege escalation (CVE-2022-1729)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* The latest Rocky Linux 8.6.z1 kernel changes need to be merged into the RT source tree to keep source parity between the two kernels. (BZ#2098244)
Security Fix(es) | Important | 2022-07-13 00:00:00+03:00 | 2022-07-13 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5565', 'https://errata.rockylinux.org/RLSA-2022:5565'] | b7f81a5ed76a90e0eb51fc8716894ce07af1894f00de69e70227b9948f149427 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225564 | RLSA-2022:5564: kernel security, bug fix, and enhancement update (Important) | The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es):
* kernel: race condition in perf_event_open leads to privilege escalation (CVE-2022-1729)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* conntrack entries linger around after test (BZ#2066356)
* Any process performing I/O doesn't fail on degraded LVM RAID and IO process hangs (BZ#2075075)
* fix data corruption caused by dm-integrity (BZ#2082184)
* Backport request of "genirq: use rcu in kstat_irqs_usr()" (BZ#2083308)
* SUT will flash once color screen during boot to OS. (BZ#2083384)
* Kernel Support Fixes for UV5 platform (BZ#2084645)
* i/o on initiator stuck when network is disrupted (4.18.0-372.9.1.el8.x86_64) (BZ#2091078)
* glock deadlock (using the dct tool) (BZ#2092073)
* Recursive locking in gfs2_fault (read/write + mmap) (BZ#2092074)
* 8.6.z backport of "vmxnet3: add support for 32 Tx/Rx queues" from BZ 2083561 (BZ#2094473)
* System freezes with callstack in dmesg: ret_from_fork (BZ#2096305)
* Need some changes in Rocky Linux8.x kernels. (BZ#2096931)
* Bad length in dpctl/dump-flows (BZ#2097796)
Enhancement(s):
* Elkhart Graphics - remove force_probe flag (BZ#2075567)
Security Fix(es) | Important | 2022-07-13 00:00:00+03:00 | 2022-07-13 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5564', 'https://errata.rockylinux.org/RLSA-2022:5564'] | e6b79e2be5eeda1dc81419aaa79e3b80d02e144bb29770dd0da9d9c68aad2478 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225470 | RLSA-2022:5470: thunderbird security update (Important) | Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 91.11.
Security Fix(es):
* Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI (CVE-2022-34468)
* Mozilla: Use-after-free in nsSHistory (CVE-2022-34470)
* Mozilla: A popup window could be resized in a way to overlay the address bar with web content (CVE-2022-34479)
* Mozilla: Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11 (CVE-2022-34484)
* Mozilla: Undesired attributes could be set as part of prototype pollution (CVE-2022-2200)
* Mozilla: An email with a mismatching OpenPGP signature date was accepted as valid (CVE-2022-2226)
* Mozilla: CSP bypass enabling stylesheet injection (CVE-2022-31744)
* Mozilla: Unavailable PAC file resulted in OCSP requests being blocked (CVE-2022-34472)
* Mozilla: Potential integer overflow in ReplaceElementsAt (CVE-2022-34481)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-06-30 00:00:00+03:00 | 2022-06-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5470', 'https://errata.rockylinux.org/RLSA-2022:5470'] | b6c26c57438a2586b8aba2b717d49f228a0fdb98837f6d4e56c79f5b649d9efa | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225469 | RLSA-2022:5469: firefox security update (Important) | Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 91.11 ESR.
Security Fix(es):
* Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI (CVE-2022-34468)
* Mozilla: Use-after-free in nsSHistory (CVE-2022-34470)
* Mozilla: A popup window could be resized in a way to overlay the address bar with web content (CVE-2022-34479)
* Mozilla: Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11 (CVE-2022-34484)
* Mozilla: Undesired attributes could be set as part of prototype pollution (CVE-2022-2200)
* Mozilla: CSP bypass enabling stylesheet injection (CVE-2022-31744)
* Mozilla: Unavailable PAC file resulted in OCSP requests being blocked (CVE-2022-34472)
* Mozilla: Potential integer overflow in ReplaceElementsAt (CVE-2022-34481)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-06-30 00:00:00+03:00 | 2022-06-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5469', 'https://errata.rockylinux.org/RLSA-2022:5469'] | c47c83a8a2e87d6ce3ccd56398c06f0ced2930f4dc8bacfc2a57ab98e1336240 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20243233 | RLSA-2024:3233: libssh security update (Low) | libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.
Security Fix(es):
* libssh: ProxyCommand/ProxyJump features allow injection of malicious code through hostname (CVE-2023-6004)
* libssh: Missing checks for return values for digests (CVE-2023-6918)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.10 Release Notes linked from the References section.
Security Fix(es) | Low | 2024-06-14 00:00:00+03:00 | 2024-06-14 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:3233', 'https://errata.rockylinux.org/RLSA-2024:3233'] | 39d6eee559a349cc705f2ae52cb30ad5fc82e8767b6dfdd7b8de3da6ff39943b | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225344 | RLSA-2022:5344: kernel-rt security and bug fix update (Important) | The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: buffer overflow in IPsec ESP transformation code (CVE-2022-27666)
* kernel: out-of-bounds read in fbcon_get_font function (CVE-2020-28915)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* kernel-rt: update RT source tree to the latest Rocky Linux-8.6.z0 Batch (BZ#2081704)
Security Fix(es) | Important | 2022-06-28 00:00:00+03:00 | 2022-06-28 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5344', 'https://errata.rockylinux.org/RLSA-2022:5344'] | 9970866da41ac1ceafcbaba82dda82ce3d9fcc958e2e7f25d461d5ccfabb8279 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225338 | RLSA-2022:5338: ruby (Moderate) | Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.
The following packages have been upgraded to a later upstream version: ruby (2.6.10). (BZ#2089374)
Security Fix(es):
* Ruby: Buffer overrun in String-to-Float conversion (CVE-2022-28739)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2022-06-28 00:00:00+03:00 | 2022-06-28 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5338', 'https://errata.rockylinux.org/RLSA-2022:5338'] | 486a2b15fe58236034172154356420ca31ed30d1c591e3681bf6a699baf3bcb9 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225337 | RLSA-2022:5337: go-toolset (Moderate) | Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.
Security Fix(es):
* golang: encoding/pem: fix stack overflow in Decode (CVE-2022-24675)
* golang: crypto/elliptic: panic caused by oversized scalar (CVE-2022-28327)
* golang: syscall: faccessat checks wrong group (CVE-2022-29526)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Update to Go 1.17.10 (BZ#2091077)
Security Fix(es) | Moderate | 2022-06-28 00:00:00+03:00 | 2022-06-28 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5337', 'https://errata.rockylinux.org/RLSA-2022:5337'] | 7be74e10325aa1169ca941b3cfe2325f00f0c244df0d185c71e69f4b866590d2 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225331 | RLSA-2022:5331: libinput security update (Moderate) | libinput is a library that handles input devices for display servers and other applications that need to directly deal with input devices.
Security Fix(es):
* libinput: format string vulnerability may lead to privilege escalation (CVE-2022-1215)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2022-06-28 00:00:00+03:00 | 2022-06-28 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5331', 'https://errata.rockylinux.org/RLSA-2022:5331'] | 42d7f9e066262e24dd40d4a080f3350f453ef60886df90d3e77f11bb0a2b0e0a | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225314 | RLSA-2022:5314: expat security update (Moderate) | Expat is a C library for parsing XML documents.
Security Fix(es):
* expat: stack exhaustion in doctype parsing (CVE-2022-25313)
* expat: integer overflow in copyString() (CVE-2022-25314)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2022-06-28 00:00:00+03:00 | 2022-06-28 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5314', 'https://errata.rockylinux.org/RLSA-2022:5314'] | 18ac444b54bee6fe092928ba417c0cf7a9b9063c4e7d6e02b643d26ddc91fcd1 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225313 | RLSA-2022:5313: curl security update (Moderate) | The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.
Security Fix(es):
* curl: OAUTH2 bearer bypass in connection re-use (CVE-2022-22576)
* curl: credential leak on redirect (CVE-2022-27774)
* curl: auth/cookie leak on redirect (CVE-2022-27776)
* curl: TLS and SSH connection too eager reuse (CVE-2022-27782)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2022-06-28 00:00:00+03:00 | 2022-06-28 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5313', 'https://errata.rockylinux.org/RLSA-2022:5313'] | 455f3092600580a23581c0c3ec8fd6369d68668b74e669f3f6ee5059054d860c | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20235050 | RLSA-2023:5050: httpd (Moderate) | The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.
Security Fix(es):
* httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2023-09-19 00:00:00+03:00 | 2023-09-19 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:5050', 'https://errata.rockylinux.org/RLSA-2023:5050'] | 62dde0f533797fa7ba066c1cfb005c0faa6e720a3f335446b6ccb6dc513b4333 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20233582 | RLSA-2023:3582: .NET 6.0 security, bug fix, and enhancement update (Important) | .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 6.0.118 and .NET Runtime 6.0.18.
The following packages have been upgraded to a later upstream version: dotnet6.0 (6.0.118). (BZ#2212378)
Security Fix(es):
* dotnet: .NET Kestrel: Denial of Service processing X509 Certificates (CVE-2023-29331)
* dotnet: vulnerability exists in NuGet where a potential race condition can lead to a symlink attack (CVE-2023-29337)
* dotnet: Remote Code Execution - Source generators issue can lead to a crash due to unmanaged heap corruption (CVE-2023-33128)
* dotnet: Bypass restrictions when deserializing a DataSet or DataTable from XML (CVE-2023-24936)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2023-08-31 00:00:00+03:00 | 2023-08-31 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:3582', 'https://errata.rockylinux.org/RLSA-2023:3582'] | fdbc939174e0c0e092b08bc07bb40251566b009e0b0c2bec92890feb2f725432 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225095 | RLSA-2022:5095: grub2, mokutil, shim, and shim-unsigned-x64 security update (Important) | The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.
The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.
Security Fix(es):
* grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733)
* grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap (CVE-2021-3695)
* grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling (CVE-2021-3696)
* grub2: Crafted JPEG image can lead to buffer underflow write in the heap (CVE-2021-3697)
* grub2: Out-of-bound write when handling split HTTP headers (CVE-2022-28734)
* grub2: shim_lock verifier allows non-kernel files to be loaded (CVE-2022-28735)
* grub2: use-after-free in grub_cmd_chainloader() (CVE-2022-28736)
* shim: Buffer overflow when loading crafted EFI images (CVE-2022-28737)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-06-16 00:00:00+03:00 | 2022-06-16 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5095', 'https://errata.rockylinux.org/RLSA-2022:5095'] | f68fc1b993e5cd93d626ba800981e9995f8cd7ee66ea85c705cee6fc0e9a5dfb | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20225046 | RLSA-2022:5046: .NET 6.0 security and bugfix update (Moderate) | .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 6.0.106 and .NET Runtime 6.0.6.
Security Fix(es):
* dotnet: NuGet Credential leak due to loss of control of third party symbol server domain (CVE-2022-30184)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2022-06-15 00:00:00+03:00 | 2022-06-15 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:5046', 'https://errata.rockylinux.org/RLSA-2022:5046'] | 374686574bb1ea857dc17149140674b48fdf5381ae174e4b86a756e4c14c4ddc | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20224991 | RLSA-2022:4991: xz security update (Important) | XZ Utils is an integrated collection of user-space file compression utilities based on the Lempel-Ziv-Markov chain algorithm (LZMA), which performs lossless data compression. The algorithm provides a high compression ratio while keeping the decompression time short.
Security Fix(es):
* gzip: arbitrary-file-write vulnerability (CVE-2022-1271)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-06-13 00:00:00+03:00 | 2022-06-13 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:4991', 'https://errata.rockylinux.org/RLSA-2022:4991'] | 4ebedcfd38aaa7059097b485af1ed01b235908d471cb63ff845b6a3672000972 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20233837 | RLSA-2023:3837: systemd security and bug fix update (Moderate) | The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelism capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups. In addition, it supports snapshotting and restoring of the system state, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. It can also work as a drop-in replacement for sysvinit.
Security Fix(es):
* systemd: privilege escalation via the less pager (CVE-2023-26604)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* systemd-pstore crashes when attempting to move standalone files out of /sys/fs/pstore (BZ#2190153)
Security Fix(es) | Moderate | 2023-08-31 00:00:00+03:00 | 2023-08-31 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:3837', 'https://errata.rockylinux.org/RLSA-2023:3837'] | cd06e54856a28528f8be857dd18f8cd6e7dd137412275bd2b212b34c15c58166 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20226542 | RLSA-2022:6542: php (Moderate) | PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.
Security Fix(es):
* Archive_Tar: allows an unserialization attack because phar: is blocked but PHAR: is not blocked (CVE-2020-28948)
* Archive_Tar: improper filename sanitization leads to file overwrites (CVE-2020-28949)
* Archive_Tar: directory traversal due to inadequate checking of symbolic links (CVE-2020-36193)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Moderate | 2022-09-15 00:00:00+03:00 | 2022-09-15 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:6542', 'https://errata.rockylinux.org/RLSA-2022:6542'] | eff31510bde2f614c0fd3f5473a39a429f29275f1bb548a3206ada5f2a7a87d6 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20224941 | RLSA-2022:4941: subversion (Important) | Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes.
Security Fix(es):
* subversion: Subversion's mod_dav_svn is vulnerable to memory corruption (CVE-2022-24070)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-06-08 00:00:00+03:00 | 2022-06-08 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:4941', 'https://errata.rockylinux.org/RLSA-2022:4941'] | 502f48980d5a027ac090c0513083dccac6f0a20502ff80bc9bea7a5990f4c3dd | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20224887 | RLSA-2022:4887: thunderbird security update (Important) | Mozilla Thunderbird is a standalone mail and newsgroup client.
This update upgrades Thunderbird to version 91.10.0.
Security Fix(es):
* Mozilla: Braille space character caused incorrect sender email to be shown for a digitally signed email (CVE-2022-1834)
* Mozilla: Cross-Origin resource's length leaked (CVE-2022-31736)
* Mozilla: Heap buffer overflow in WebGL (CVE-2022-31737)
* Mozilla: Browser window spoof using fullscreen mode (CVE-2022-31738)
* Mozilla: Register allocation problem in WASM on arm64 (CVE-2022-31740)
* Mozilla: Uninitialized variable leads to invalid memory read (CVE-2022-31741)
* Mozilla: Memory safety bugs fixed in Firefox 101 and Firefox ESR 91.10 (CVE-2022-31747)
* Mozilla: Querying a WebAuthn token with a large number of allowCredential entries may have leaked cross-origin information (CVE-2022-31742)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-06-02 00:00:00+03:00 | 2022-06-02 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:4887', 'https://errata.rockylinux.org/RLSA-2022:4887'] | 4a6b4ff550f649a17bd7656575ca75e4bbfd2918a0406671e9d4d22d0272d46f | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20235742 | RLSA-2023:5742: java-11-openjdk security and bug fix update (Moderate) | The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.
Security Fix(es):
* OpenJDK: certificate path validation issue during client authentication (8309966) (CVE-2023-22081)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Additional validity checks in the handling of Zip64 files, JDK-8302483, were introduced in the 11.0.20 release of OpenJDK, causing the use of some valid zip files to now fail with an error. This release, 11.0.20.1, allows for zero-length headers and additional padding produced by some Zip64 creation tools. With both releases, the checks can be disabled using -Djdk.util.zip.disableZip64ExtraFieldValidation=true. (RHBZ#2237170)
* A maximum signature file size property, jdk.jar.maxSignatureFileSize, was introduced in the 11.0.20 release of OpenJDK by JDK-8300596, with a default of 8 MB. This default proved to be too small for some JAR files. This release, 11.0.20.1, increases it to 16 MB.
* The serviceability agent would print an exception when encountering null addresses while producing thread dumps. These null values are now handled appropriately. (JDK-8243210, Rocky Linux-2763)
* The /usr/bin/jfr alternative is now owned by the java-11-openjdk package (Rocky Linux-13559)
* The jcmd tool is now provided by the java-11-openjdk-headless package, rather than java-11-openjdk-devel, to make it more accessible (Rocky Linux-13566)
Security Fix(es) | Moderate | 2023-10-24 00:00:00+03:00 | 2023-10-24 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2023:5742', 'https://errata.rockylinux.org/RLSA-2023:5742'] | 2b257ef0a9adc8fc68bf044c446203ec0f9887908de650f56f89164cfded7c7f | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20224872 | RLSA-2022:4872: firefox security update (Important) | Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
This update upgrades Firefox to version 91.10.0 ESR.
Security Fix(es):
* Mozilla: Cross-Origin resource's length leaked (CVE-2022-31736)
* Mozilla: Heap buffer overflow in WebGL (CVE-2022-31737)
* Mozilla: Browser window spoof using fullscreen mode (CVE-2022-31738)
* Mozilla: Register allocation problem in WASM on arm64 (CVE-2022-31740)
* Mozilla: Uninitialized variable leads to invalid memory read (CVE-2022-31741)
* Mozilla: Memory safety bugs fixed in Firefox 101 and Firefox ESR 91.10 (CVE-2022-31747)
* Mozilla: Querying a WebAuthn token with a large number of allowCredential entries may have leaked cross-origin information (CVE-2022-31742)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-06-01 00:00:00+03:00 | 2022-06-01 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:4872', 'https://errata.rockylinux.org/RLSA-2022:4872'] | 49ca84d61cf23a3bc7e1e636783b1eeaf06e8dfec7b0647b3b7d3f0f037298c0 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20224855 | RLSA-2022:4855: postgresql (Important) | PostgreSQL is an advanced object-relational database management system (DBMS).
The following packages have been upgraded to a later upstream version: postgresql (13.7).
Security Fix(es):
* postgresql: Autovacuum, REINDEX, and others omit "security restricted operation" sandbox (CVE-2022-1552)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-06-01 00:00:00+03:00 | 2022-06-01 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:4855', 'https://errata.rockylinux.org/RLSA-2022:4855'] | e895f736bcdede1db568c4cfcb4f4714367b06eb6fe12da8a7e3db09a13c9452 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20224807 | RLSA-2022:4807: postgresql (Important) | PostgreSQL is an advanced object-relational database management system (DBMS).
The following packages have been upgraded to a later upstream version: postgresql (12.11).
Security Fix(es):
* postgresql: Autovacuum, REINDEX, and others omit "security restricted operation" sandbox (CVE-2022-1552)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-05-31 00:00:00+03:00 | 2022-05-31 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:4807', 'https://errata.rockylinux.org/RLSA-2022:4807'] | f5cc4b79ab51fb9796a6228c976ba17da29ff1d9d2c74fd73bbe7606f96af5cc | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20224805 | RLSA-2022:4805: postgresql (Important) | PostgreSQL is an advanced object-relational database management system (DBMS).
The following packages have been upgraded to a later upstream version: postgresql (10.21).
Security Fix(es):
* postgresql: Autovacuum, REINDEX, and others omit "security restricted operation" sandbox (CVE-2022-1552)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es) | Important | 2022-05-30 00:00:00+03:00 | 2022-05-30 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2022:4805', 'https://errata.rockylinux.org/RLSA-2022:4805'] | ab9e96ceb5aa33c70886d59dab3ee68ee3764fb4890e0b3f9d3771e7a4198887 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 | |
oval:org.rockylinux.rlsa:def:20243047 | RLSA-2024:3047: 389-ds (Moderate) | 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.
Security Fix(es):
* 389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr) (CVE-2024-1062)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.10 Release Notes linked from the References section.
Security Fix(es) | Moderate | 2024-06-14 00:00:00+03:00 | 2024-06-14 00:00:00+03:00 | ['Rocky Linux 8'] | ['RLSA-2024:3047', 'https://errata.rockylinux.org/RLSA-2024:3047'] | 5c34a31a56ea35b261995818fb5efa26d82917365cd8606ee5fa7937b48e6bf0 | 2026-05-30 01:54:38.760184+03:00 | 2026-06-29 20:18:03.608226+03:00 |