Skip to content

Commit 847588a

Browse files
committed
more CVEs already fixed (freshmaker issues)
Signed-off-by: Nick Boldt <[email protected]>
1 parent 7dd6845 commit 847588a

File tree

2 files changed

+17
-0
lines changed

2 files changed

+17
-0
lines changed

modules/release-notes/list-fixed-security-issues-in-rpm-1.3.2.txt

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ CVE-2024-3596, freeradius: forgery attack, https://bugzilla.redhat.com/show_bug.
77
CVE-2024-30203, emacs: Gnus treats inline MIME contents as trusted, https://bugzilla.redhat.com/show_bug.cgi?id=2280296
88
CVE-2024-30204, emacs: LaTeX preview is enabled by default for e-mail attachments, https://bugzilla.redhat.com/show_bug.cgi?id=2280297
99
CVE-2024-30205, emacs: Org mode considers contents of remote files to be trusted, https://bugzilla.redhat.com/show_bug.cgi?id=2280298
10+
# https://errata.engineering.redhat.com/advisory/142796 -> https://access.redhat.com/errata/RHSA-2024:9541
1011
CVE-2024-50602, libexpat: expat: DoS via XML_ResumeParser, https://bugzilla.redhat.com/show_bug.cgi?id=2321987
1112
CVE-2024-2236, libgcrypt: vulnerable to Marvin Attack, https://bugzilla.redhat.com/show_bug.cgi?id=2245218
1213
CVE-2024-0450, python: The zipfile module is vulnerable to zip-bombs leading to denial of service, https://bugzilla.redhat.com/show_bug.cgi?id=2276525
@@ -20,3 +21,7 @@ CVE-2024-24791, net/http: Denial of service due to improper 100-continue handlin
2021

2122
# https://errata.engineering.redhat.com/advisory/128795 includes 478 bugs fixed in RHEL 9.5 with kernel-5.14.0-503.11.1.el9_5 - only listing one of them here
2223
CVE-2024-45005, kernel: KVM: s390: fix validity interception issue when gisa is switched off, https://bugzilla.redhat.com/show_bug.cgi?id=2309868
24+
# https://errata.engineering.redhat.com/advisory/142823 -> https://access.redhat.com/errata/RHSA-2024:9605
25+
CVE-2024-42283, kernel
26+
CVE-2024-46824, kernel
27+
CVE-2024-46858, kernel

modules/release-notes/snip-fixed-security-issues-in-rpm-1.3.2.adoc

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,9 +33,21 @@ A flaw was found in Emacs. When Emacs is used as an email client, a preview of a
3333
link:https://access.redhat.com/security/cve/CVE-2024-30205[CVE-2024-30205]::
3434
A flaw was found in Emacs. Org mode considers the content of remote files, such as files opened with TRAMP on remote systems, to be trusted, resulting in arbitrary code execution.
3535

36+
link:https://access.redhat.com/security/cve/CVE-2024-42283[CVE-2024-42283]::
37+
In the Linux kernel, the following vulnerability has been resolved:
38+
net: nexthop: Initialize all fields in dumped nexthops
39+
3640
link:https://access.redhat.com/security/cve/CVE-2024-45005[CVE-2024-45005]::
3741
In the Linux kernel, the following vulnerability has been resolved:
3842
KVM: s390: fix validity interception issue when gisa is switched off
3943

44+
link:https://access.redhat.com/security/cve/CVE-2024-46824[CVE-2024-46824]::
45+
In the Linux kernel, the following vulnerability has been resolved:
46+
iommufd: Require drivers to supply the cache_invalidate_user ops
47+
48+
link:https://access.redhat.com/security/cve/CVE-2024-46858[CVE-2024-46858]::
49+
In the Linux kernel, the following vulnerability has been resolved:
50+
mptcp: pm: Fix uaf in __timer_delete_sync
51+
4052
link:https://access.redhat.com/security/cve/CVE-2024-50602[CVE-2024-50602]::
4153
A security issue was found in Expat (libexpat). A crash can be triggered in the XML_ResumeParser function due to XML_StopParser's ability to stop or suspend an unstarted parser, which can lead to a denial of service.

0 commit comments

Comments
 (0)