Linux Security Roundup: SUSE Kernel, rsync, and Exim CVEs

Published by

The latest Linux security roundup highlights significant updates, with SUSE releasing a kernel patch addressing 133 CVEs, while Debian and Ubuntu also rolled out important updates for rsync, dovecot, and Exim, among others. Notably, vulnerabilities in Slackware's groff and pcre2 libraries remind us of long-standing security issues, some dating back decades, while AlmaLinux and Oracle Linux also issued multiple security advisories for essential packages. Users of Fedora and Rocky Linux should prioritize updates for Chromium and Ruby, respectively, due to their critical vulnerabilities. Administrators are advised to carefully assess the advisory tables and apply the necessary patches, keeping in mind that some updates may require system reboots



Linux Security Roundup: SUSE Kernel, rsync, and Exim CVEs

SUSE led today's Linux patch wave with a 133-CVE kernel update that still needs a reboot, though the real standouts were the bugs you'd expect to be long fixed. Debian shipped rsync with 33 CVEs and dovecot with 25, while Debian's OpenStack and Slackware's 26-year-old groff command-injection holes made the week feel oddly retro. Ubuntu's Exim brought proxy-protocol code execution, but the most awkward moment went to its curl cleanup notice targeting the still-supported 14.04 LTS. If any of this software runs on boxes you manage, the advisory tables are worth a scroll and the reboot is unavoidable.

Linux Security Roundup: SUSE Kernel, rsync, and Exim CVEs @ Linux Compatible