ALT-BU-2024-14979-1
Branch sisyphus_loongarch64 update bulletin.
Package jose updated to version 14-alt1 for branch sisyphus_loongarch64.
Closed vulnerabilities
BDU:2024-02461
Уязвимость модуля языка С для подписи и шифрования объектов JSON latchset Jose, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2023-50967
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
- https://github.com/latchset/jose
- https://github.com/latchset/jose
- https://github.com/P3ngu1nW/CVE_Request/blob/main/latch-jose.md
- https://github.com/P3ngu1nW/CVE_Request/blob/main/latch-jose.md
- FEDORA-2024-f98bdff610
- FEDORA-2024-f98bdff610
- FEDORA-2024-a94b67a7b2
- FEDORA-2024-a94b67a7b2
- FEDORA-2024-2cface5aba
- FEDORA-2024-2cface5aba
Package sssd updated to version 2.9.5-alt1 for branch sisyphus_loongarch64.
Closed vulnerabilities
BDU:2024-04108
Уязвимость сервиса управления доступом к удаленным каталогам и механизма аутентификации SSSD, связанная с неправильной авторизацией, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-02-06
CVE-2023-3758
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
- RHSA-2024:1919
- RHSA-2024:1919
- RHSA-2024:1920
- RHSA-2024:1920
- RHSA-2024:1921
- RHSA-2024:1921
- RHSA-2024:1922
- RHSA-2024:1922
- RHSA-2024:2571
- RHSA-2024:2571
- RHSA-2024:3270
- RHSA-2024:3270
- https://access.redhat.com/security/cve/CVE-2023-3758
- https://access.redhat.com/security/cve/CVE-2023-3758
- RHBZ#2223762
- RHBZ#2223762
- https://github.com/SSSD/sssd/pull/7302
- https://github.com/SSSD/sssd/pull/7302
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RV3HIZI3SURBUQKSOOL3XE64OOBQ2HTK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XEP62IDS7A55D5UHM6GH7QZ7SQFOAPVF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XMORAO2BDDA5YX4ZLMXDZ7SM6KU47SY5/
Closed bugs
Добавить зависимость на sssd-dbus к sssd-tools
Package runc updated to version 1.2.0-alt1.0.port for branch sisyphus_loongarch64.
Closed bugs
Docker на Loongson не может запустить базовый образ