Linux Security Roundup: Chromium, OpenSSH, Node.js, PHP, and Kernel CVEs
Eight major Linux distributions shipped security errata today, addressing over three hundred CVEs across the standard infrastructure stack. The coordinated update targets recurring HTTP/2 memory exhaustion flaws, Go standard library bypasses, and critical bugs in OpenSSH, Chromium, and PHP. Administrators running internet-facing services should prioritize patching immediately, especially on systems relying on OpenShift, FreeIPA, or unpatched Node.js runtimes. Once the package manager finishes updating, expect to manually restart dependent services like SSSD, SPICE vdagent, and the OpenSSH daemon.
Linux Security Roundup: Chromium, OpenSSH, Node.js, PHP, and Kernel CVEs @ Linux Compatible
Linux Security Roundup: Chromium, OpenSSH, Node.js, PHP, and Kernel CVEs
Eight major Linux distributions have released synchronized security updates addressing over three hundred Common Vulnerabilities and Exposures (CVEs), focusing on critical issues in OpenSSH, Chromium, PHP, and HTTP/2 memory exhaustion flaws. System administrators are urged to prioritize these updates, particularly for internet-facing services, and to restart dependent services after applying the patches. Notable updates include a significant Chromium upgrade in Debian, which addressed over two hundred CVEs, and critical vulnerabilities in OpenSSH for Ubuntu. Additionally, various distributions introduced fixes for the Go standard library, PHP, and multiple kernel vulnerabilities, emphasizing the importance of routine maintenance to mitigate potential security risks
