Linux Security Roundup: 230 Browser CVEs, Critical Directory Server Flaw

Published by

The latest Linux security roundup highlights significant updates, including a substantial 230 vulnerabilities addressed in browser patches by Gentoo and SUSE, as well as critical updates for directory servers from AlmaLinux and Oracle that could grant attackers Directory Manager access. Other notable fixes include routine updates for DNS tooling across Fedora, Red Hat, and Debian, alongside various security patches for packages like OpenSSL and FFmpeg. The updates also feature a major Perl update on Rocky Linux that affected over 200 downstream packages, emphasizing the interconnected nature of software ecosystems. System administrators are urged to prioritize these updates, particularly those labeled critical, to ensure robust security for their systems



Linux Security Roundup: 230 Browser CVEs, Critical Directory Server Flaw

Today's Linux security roundup delivers some of the year's largest browser patches, including Gentoo's 35-CVE roundup for Chrome, Edge, and Chromium alongside SUSE's 230-vulnerability chromedriver fix. The fixes warrant the most scrutiny are the Critical-rated 389-ds-base updates from both AlmaLinux and Oracle Linux, which hand attackers Directory Manager access. DNS tooling appears repeatedly across Fedora, Red Hat, and Debian as the resolver ecosystem keeps generating trouble. The rest of the batch ranges from routine openssl kernel and ffmpeg bumps to a Perl update on Rocky Linux that quietly rewrote more than two hundred downstream packages.

Linux Security Roundup: 230 Browser CVEs, Critical Directory Server Flaw @ Linux Compatible