News, Alert e Bollettini di sicurezza Microsoft e Linux
Microsoft (MSRC Security Update Guide)
- CVE-2026-63831 mac802154: llsec: add skb_cow_data() before in-place cryptoon 21 Luglio 2026 at 8:44 am
Information published.
- CVE-2026-63796 ocfs2: reject oversized group bitmap descriptorson 21 Luglio 2026 at 8:44 am
Information published.
- CVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout()on 21 Luglio 2026 at 8:44 am
Information published.
- CVE-2026-63824 KEYS: fix overflow in keyctl_pkey_params_get_2()on 21 Luglio 2026 at 8:44 am
Information published.
- CVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob writeon 21 Luglio 2026 at 8:42 am
Information published.
- CVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.on 21 Luglio 2026 at 8:42 am
Information published.
- CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.on 21 Luglio 2026 at 8:41 am
Information published.
- CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT recordon 21 Luglio 2026 at 8:41 am
Information published.
- CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path indexon 21 Luglio 2026 at 8:41 am
Information published.
- CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted locationon 21 Luglio 2026 at 8:41 am
Information published.
- CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the rowon 21 Luglio 2026 at 8:41 am
Information published.
- CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted = SQL operators on texton 21 Luglio 2026 at 8:41 am
Information published.
- CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK recordon 21 Luglio 2026 at 8:41 am
Information published.
- CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of serviceon 21 Luglio 2026 at 8:40 am
Information published.
- CVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loopon 21 Luglio 2026 at 8:39 am
Information published.
- CVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsgon 21 Luglio 2026 at 8:39 am
Information published.
- CVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_doneon 21 Luglio 2026 at 8:39 am
Information published.
- CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied qon 21 Luglio 2026 at 8:05 am
Information published.
- CVE-2026-42769 Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdateon 21 Luglio 2026 at 8:05 am
Information published.
- CVE-2026-45447 Heap Use-After-Free in the PKCS7_verify() Functionon 21 Luglio 2026 at 8:05 am
Information published.
- CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.on 21 Luglio 2026 at 8:05 am
Information published.
- CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.on 21 Luglio 2026 at 8:05 am
Information published.
- CVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on erroron 21 Luglio 2026 at 8:05 am
Information published.
- CVE-2026-64146 erofs: fix metabuf leak in inode xattr initializationon 21 Luglio 2026 at 8:05 am
Information published.
- CVE-2026-63974 Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device closeon 21 Luglio 2026 at 8:05 am
Information published.
- CVE-2026-63978 net/handshake: Drain pending requests at net namespace exiton 21 Luglio 2026 at 8:04 am
Information published.
- CVE-2026-63999 ethtool: rss: fix indir_table and hkey leak on get_rxfh failureon 21 Luglio 2026 at 8:04 am
Information published.
- CVE-2026-64017 blk-mq: pop cached request if it is usableon 21 Luglio 2026 at 8:04 am
Information published.
- CVE-2026-63979 net/handshake: hand off the pinned file reference to accept_doiton 21 Luglio 2026 at 8:04 am
Information published.
- CVE-2026-64060 netfs: Fix leak of request in netfs_write_begin() error handlingon 21 Luglio 2026 at 8:04 am
Information published.
Linux (Community’s Center for Security)
- Mageia perl-CGI-Session Important Predictable IDs CVE-2026-56016by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia 10 PHP 8.4 Critical Memory Corruption CVE-2026-14355by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia Imager Critical Heap Buffer Overflow Denial Of Service 2026-0284by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia Perl JavaScript Minifier Important Memory Leak Fix 2026-0283by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia GraphicsMagick Security Advisory CVE-2026-46523 Use-After-Free Issueby LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia Python-nltk Important Local File Read Vulnerability CVE-2026-54293by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia nilfs-utils Severe Memory Exhaustion Vulnerability CVE-2026-55392by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia nginx Critical Proxy and Charset Module Vulnerabilities 2026-0279by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia sqlite3 Important Memory Corruption Buffer Overflow Vuln 2026-0278by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia XMLStarlet Important XML External Entity Vuln 2026-0277by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia Golang Critical Security Advisory CVE-2026-42504 CVE-2026-42507by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia 10 Haveged Important Privilege Escalation CVE-2026-41054by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia PHP Critical Memory Corruption Vulnerability CVE-2026-14355by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Mageia Libssh2 Critical DoS and Buffer Overflow Vuln 2026-0273by LinuxSecurity Advisories on 20 Luglio 2026 at 7:07 pm
Security update
- Oracle 8 hplip Important Buffer Overflow Fix ELSA-2026-40894by LinuxSecurity Advisories on 20 Luglio 2026 at 6:58 pm
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 8 Kernel Important Security Advisory ELSA-2026-39179by LinuxSecurity Advisories on 20 Luglio 2026 at 6:58 pm
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
- Oracle ELSA-2026-38901 perl-DBI Important Buffer Overflow Fixby LinuxSecurity Advisories on 20 Luglio 2026 at 6:58 pm
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 8 Container-Tools Important Fix ELSA-2026-38504 CVE-2026-33811by LinuxSecurity Advisories on 20 Luglio 2026 at 6:58 pm
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 9 PHP 8.2 Low Bug Fix Advisory ELSA-2026-40416by LinuxSecurity Advisories on 20 Luglio 2026 at 6:58 pm
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 9 ELSA-2026-39323 Pacemaker Important Integer Overflow Fixby LinuxSecurity Advisories on 20 Luglio 2026 at 6:58 pm
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 10 libtiff Important Heap Overflow Fix ELSA-2026-41892by LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 10 Advisory ELSA-2026-36189 perl-HTTP-Daemon Important Fixby LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 10 glibc Moderate Buffer Overflow Fix ELSA-2026-33092by LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 10 ELSA-2026-27740 ipp-usb Moderate CVE-2026-32281by LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 10 ELSA-2026-27733 Firefox Important Security Fixby LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 10 mod_http2 Important DoS Vulnerability ELSA-2026-25225by LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 10 Kernel Critical Security Advisory ELSA-2026-25191by LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
- Important Security Alert for Oracle Linux 10 Image-Builder ELSA-2026-22937by LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux 10 mod_http2 Moderate DoS Advisory ELSA-2026-22528by LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
- Oracle Linux Thunderbird Important Security Advisory ELSA-2026-22325by LinuxSecurity Advisories on 20 Luglio 2026 at 6:57 pm
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: