Security Leftovers

-
Security updates for Tuesday [LWN.net]
Security updates have been issued by CentOS (java-11-openjdk), Debian (aide, apr, ipython, openjdk-11, qt4-x11, and strongswan), Fedora (binaryen and rust), Mageia (expat, htmldoc, libreswan, mysql-connector-c++, phpmyadmin, python-celery, python-numpy, and webkit2), openSUSE (kernel and virtualbox), Red Hat (etcd, libreswan, nodejs:14, OpenJDK 11.0.14, OpenJDK 17.0.2, and rpm), Slackware (expat), SUSE (java-1_7_1-ibm, kernel, and zxing-cpp), and Ubuntu (strongswan).
-
Linux kernel bug can let hackers escape Kubernetes containers [Ed: Kubernetes and containers do not mean Linux kernel, but when a site is determined to boost Microsoft everything will always be blamed on "Linux"]
A vulnerability affecting Linux kernel and tracked as CVE-2022-0185 can be used to escape containers in Kubernetes, giving access to resources on the host system.
-
Major Linux PolicyKit security vulnerability uncovered: Pwnkit | ZDNet
If it's not one thing, it's another. After one real Linux problem -- the heap overflow bug in the Linux kernel's fs/fs_context.c program -- is found and fixed, then a new security problem is discovered. This time security company Qualys has uncovered a truly dangerous memory corruption vulnerability in polkit's pkexec, CVE-2021-4034.
Polkit, formerly known as PolicyKit, is a systemd SUID-root program. It's installed by default in every major Linux distribution.
-
- Login or register to post comments
Printer-friendly version
- 4854 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
today's howtos
| The 10 Best Linux Apps for Musicians
If you're a musician of any kind, from beginner to professional, Linux provides an amazing assortment of free, yet powerful, platforms and applications that will boost your productivity and help you to show off your creativity.
Don't let the fact that these apps are free wrongly influence your judgment. They are high-quality, professional-grade applications that rival even the most well-known, high-priced, commercial applications. These are 10 of the best Linux apps for musicians of all levels.
|
GNOME and KDE: This Week in GNOME, Qt6 and KF6
| The 5 best Application Launchers for UbuntuEvery operating system comes with an application launcher where you have to mouse over the entire menu to launch an application. But, unlike other operating systems, Linux allows us to install other launchers as an alternative. In this post, We came up with the five best application launchers for Ubuntu and their installation process.
Ubuntu has a default application launcher, i.e., GNOME Shell application overview. If you are a beginner or a tech professional, browsing the entire menu to launch an application is quite bothersome. Linux community offers a wide variety of application launchers. From a rich UX-based to a bare minimum, Linux has everything to offer.
These application launchers offer many themes and come with a lot of customization. Choosing the right application launcher as per your need might be difficult. That’s why we came up with the five best application launchers. Here are the top 5 application launchers for your Ubuntu.
|
Systemd security
A new Polkit vulnerability
Microsoft boosters are calling systemd "Linux"
Linux system service bug gives root on all major distros, exploit released
"Linux" vuln
Linux vulnerability can be 'easily exploited' for local privilege escalation, researchers say | VentureBeat
Two more
Control Web Panel Security Exploit Leaves 200K Linux Servers Vulnerable To Remote Hacks | HotHardware
Serious Linux privilege escalation bug lay hidden for 12 years - Security - Software - iTnews
A Polkit Vulnerability Gives Root on All Major Linux Distros
A Polkit Vulnerability Gives Root on All Major Linux Distros
Dan Goodin
A bug lurking for 12 years gives attackers root on every major Linux distro
Bryan Cockfield
Major Bug Grants Root For All Major Linux Distributions | Hackaday
Duo
Jan 26, 2022 Serious Privilege Escalation Flaw in Linux Component Patched By Dennis Fisher
SiliconANGLE
12-year-old vulnerability in Linux gives attackers root privileges - SiliconANGLE [Ed: Systemd is not Linux]
SoylentNews
Major Linux PolicyKit Security Vulnerability Uncovered: Pwnkit - SoylentNews
Easily Exploitable Linux Flaw Exposes All Distributions: Qualys
Easily Exploitable Linux Flaw Exposes All Distributions: Qualys | eSecurityPlanet
Local privilege escalation in systemnd spun as doom for "Linux"
Serious PwnKit flaw in default Linux installations requires urgent patching
PolKit vulnerability can give attackers root on many Linux distros (CVE-2021-4034)
Linux Bug in All Major Distros: 'An Attacker's Dream Come True'
Local privilege escalation vulnerability found on 'polkit' program found on every Linux variant
Lawrence Abrams, a Microsoft booster, framing a VMware...
Linux version of LockBit ransomware targets VMware ESXi servers
[Ed: Lawrence Abrams, a Microsoft booster, framing a VMware issue as "Linux"]