Linux Security Roundup: Red Hat Flags 3 Critical CVEs, Ubuntu PyJWT Fix Ships
Debian, Fedora, Red Hat, Rocky Linux, SUSE, and Ubuntu all pushed fresh security updates this week. Red Hat flagged three Critical advisories led by the unbound DNS resolver, while Ubuntu's PyJWT notice adds a signature-bypass that lets attackers forge valid tokens. Debian's libheif update carries seven CVEs plus eleven non-numbered advisories, and Fedora's Chromium build quietly closes more than 100 CVEs in one release. The takeaway is simple: patch the DNS resolver and token forgery first, then clear the rest when convenient.
Linux Security Roundup: Red Hat Flags 3 Critical CVEs, Ubuntu PyJWT Fix Ships @ Linux Compatible
Linux Security Roundup: Red Hat Flags 3 Critical CVEs, Ubuntu PyJWT Fix Ships
Linux distributions, including Red Hat, Ubuntu, Debian, Fedora, Rocky Linux, and SUSE, have recently released security updates addressing various vulnerabilities, with Red Hat highlighting three critical advisories, particularly for the unbound DNS resolver and Red Hat Identity Management. Ubuntu's PyJWT update fixes five CVEs, including a significant signature-bypass vulnerability that could allow token forgery. Debian's updates cover multiple packages, with a focus on libheif, which has several CVEs related to untrusted file processing. Users are advised to prioritize patching critical vulnerabilities, particularly those related to DNS resolution and token forgery, before addressing the rest of the updates
