ALT-PU-2025-15767-1

Обновление пакета strongswan в ветке sisyphus_loongarch64

Версия6.0.4-alt1
Задание#0
Опубликовано2025-12-13
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (2)

CVE-2025-62291
HIGH8.1

In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.

Опубликовано: 2026-01-16Изменено: 2026-04-15
CVSS 3.xВЫСОКАЯ 8.1
CVSS:3.x/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2025-9615
LOW3.3

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

Опубликовано: 2026-01-26Изменено: 2026-04-15
CVSS 3.xНИЗКАЯ 3.3
CVSS:3.x/CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N