Linux Security Roundup: Chromium's 230 CVEs, Empty-Key JWT Flaw, and More Distro Patches

Published by

Linux distributions, including Fedora, Debian, Oracle, and Ubuntu, have issued security advisories, with a notable update for Chromium that addresses 230 CVEs, alongside other important fixes. A significant flaw was discovered in Debian's ruby-jwt, where an empty key can validate as a legitimate HMAC secret, allowing attackers to forge tokens. Additionally, Fedora's update for Dovecot includes critical vulnerabilities related to arbitrary code execution and authentication bypass, while Oracle has rolled out ten advisories addressing various networking bugs across multiple versions. Other updates include fixes for Ubuntu's rclone, which improperly managed unauthenticated calls, allowing arbitrary command execution, emphasizing the need for users to apply these updates promptly



Linux Security Roundup: Chromium's 230 CVEs, Empty-Key JWT Flaw, and More Distro Patches

Linux distros including Fedora, Debian, Oracle, and Ubuntu released a fresh wave of security advisories, led by a Chromium update with 230 CVEs rather than just the expected kernel patches. The most elegant flaw sits in Debian's ruby-jwt, where an empty key still validates as a legitimate HMAC secret, letting attackers accept forged tokens across HS256, HS384, and HS512. Other standouts include Dovecot 2.4.5 with 17 CVEs covering RCE and authentication bypass, Oracle's ten-advisory batch that clearly had been accumulating, and Ubuntu's rclone fix that closes a remote command-execution hole.

Linux Security Roundup: Chromium's 230 CVEs, Empty-Key JWT Flaw, and More Distro Patches @ Linux Compatible