From 22bc39ed12fa34e39fcf5a2559a7f2135d98e1b1 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 14 Aug 2022 14:28:39 +0000 Subject: [ GLSA 202208-23 ] Xen: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/810341 Bug: https://bugs.gentoo.org/812485 Bug: https://bugs.gentoo.org/816882 Bug: https://bugs.gentoo.org/825354 Bug: https://bugs.gentoo.org/832039 Bug: https://bugs.gentoo.org/835401 Bug: https://bugs.gentoo.org/850802 Signed-off-by: GLSAMaker Signed-off-by: Sam James --- glsa-202208-23.xml | 88 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 88 insertions(+) create mode 100644 glsa-202208-23.xml diff --git a/glsa-202208-23.xml b/glsa-202208-23.xml new file mode 100644 index 000000000000..dcdd7318172f --- /dev/null +++ b/glsa-202208-23.xml @@ -0,0 +1,88 @@ + + + + Xen: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in Xen, the worst of which could result in remote code execution (guest sandbox escape). + xen,xen-tools + 2022-08-14 + 2022-08-14 + 810341 + 812485 + 816882 + 825354 + 832039 + 835401 + 850802 + remote + + + 4.15.3 + 4.15.3 + + + 4.15.3 + 4.15.3 + + + +

Xen is a bare-metal hypervisor.

+
+ +

Multiple vulnerabilities have been discovered in Xen. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Xen users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/xen-4.15.3" + + +

All Xen tools users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/xen-tools-4.15.3" + +
+ + CVE-2021-28694 + CVE-2021-28695 + CVE-2021-28696 + CVE-2021-28697 + CVE-2021-28698 + CVE-2021-28699 + CVE-2021-28700 + CVE-2021-28701 + CVE-2021-28702 + CVE-2021-28710 + CVE-2022-21123 + CVE-2022-21125 + CVE-2022-21166 + CVE-2022-23033 + CVE-2022-23034 + CVE-2022-23035 + CVE-2022-26362 + CVE-2022-26363 + CVE-2022-26364 + XSA-378 + XSA-379 + XSA-380 + XSA-382 + XSA-383 + XSA-384 + XSA-386 + XSA-390 + XSA-401 + XSA-402 + XSA-404 + + ajak + sam +
\ No newline at end of file -- cgit v1.2.3-65-gdbad From db5361e1e42ef0dfb4d6eda6648cae61bea60edf Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 14 Aug 2022 14:29:01 +0000 Subject: [ GLSA 202208-24 ] GNU C Library: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/803437 Bug: https://bugs.gentoo.org/807935 Bug: https://bugs.gentoo.org/831096 Bug: https://bugs.gentoo.org/831212 Signed-off-by: GLSAMaker Signed-off-by: Sam James --- glsa-202208-24.xml | 50 ++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 glsa-202208-24.xml diff --git a/glsa-202208-24.xml b/glsa-202208-24.xml new file mode 100644 index 000000000000..68d2b4e5456e --- /dev/null +++ b/glsa-202208-24.xml @@ -0,0 +1,50 @@ + + + + GNU C Library: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in the GNU C Library, the worst of which could result in denial of service. + glibc + 2022-08-14 + 2022-08-14 + 803437 + 807935 + 831096 + 831212 + remote + + + 2.34 + 2.34 + + + +

The GNU C library is the standard C library used by Gentoo Linux systems. It provides programs with basic facilities and interfaces to system calls. ld.so is the dynamic linker which prepares dynamically linked programs for execution by resolving runtime dependencies and related functions.

+
+ +

Multiple vulnerabilities have been discovered in GNU C Library. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All GNU C Library users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-libs/glibc-2.34-r7" + +
+ + CVE-2021-3998 + CVE-2021-3999 + CVE-2021-35942 + CVE-2021-38604 + CVE-2022-23218 + CVE-2022-23219 + + ajak + sam +
\ No newline at end of file -- cgit v1.2.3-65-gdbad From 3212eacb7aa1bccb5bf765cd0a4fb91d206ad2c5 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 14 Aug 2022 14:29:30 +0000 Subject: [ GLSA 202208-25 ] Chromium, Google Chrome, Microsoft Edge, QtWebEngine: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/773040 Bug: https://bugs.gentoo.org/787950 Bug: https://bugs.gentoo.org/800181 Bug: https://bugs.gentoo.org/810781 Bug: https://bugs.gentoo.org/815397 Bug: https://bugs.gentoo.org/828519 Bug: https://bugs.gentoo.org/829161 Bug: https://bugs.gentoo.org/834477 Bug: https://bugs.gentoo.org/835397 Bug: https://bugs.gentoo.org/835761 Bug: https://bugs.gentoo.org/836011 Bug: https://bugs.gentoo.org/836381 Bug: https://bugs.gentoo.org/836777 Bug: https://bugs.gentoo.org/836830 Bug: https://bugs.gentoo.org/837497 Bug: https://bugs.gentoo.org/838049 Bug: https://bugs.gentoo.org/838433 Bug: https://bugs.gentoo.org/838682 Bug: https://bugs.gentoo.org/841371 Bug: https://bugs.gentoo.org/843035 Bug: https://bugs.gentoo.org/843728 Bug: https://bugs.gentoo.org/847370 Bug: https://bugs.gentoo.org/847613 Bug: https://bugs.gentoo.org/848864 Bug: https://bugs.gentoo.org/851003 Bug: https://bugs.gentoo.org/851009 Bug: https://bugs.gentoo.org/853229 Bug: https://bugs.gentoo.org/853643 Bug: https://bugs.gentoo.org/854372 Signed-off-by: GLSAMaker Signed-off-by: Sam James --- glsa-202208-25.xml | 284 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 284 insertions(+) create mode 100644 glsa-202208-25.xml diff --git a/glsa-202208-25.xml b/glsa-202208-25.xml new file mode 100644 index 000000000000..02c46c6d6195 --- /dev/null +++ b/glsa-202208-25.xml @@ -0,0 +1,284 @@ + + + + Chromium, Google Chrome, Microsoft Edge, QtWebEngine: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution. + chromium,google-chrome,microsoft-edge,qtwebengine + 2022-08-14 + 2022-08-14 + 828519 + 834477 + 835397 + 836011 + 836381 + 836777 + 838049 + 838433 + 841371 + 843728 + 847370 + 851003 + 853643 + 773040 + 787950 + 800181 + 810781 + 815397 + 829161 + 835761 + 836830 + 847613 + 853229 + 837497 + 838682 + 843035 + 848864 + 851009 + 854372 + remote + + + 5.15.5_p20220618 + 5.15.5_p20220618 + + + 103.0.5060.53 + 103.0.5060.53 + + + 103.0.5060.53 + 103.0.5060.53 + + + 101.0.1210.47 + 101.0.1210.47 + + + +

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. + +Google Chrome is one fast, simple, and secure browser for all your devices. + +Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier.

+
+ +

Multiple vulnerabilities have been discovered in Chromium and its derivatives. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Chromium users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/chromium-103.0.5060.53" + + +

All Chromium binary users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/chromium-bin-103.0.5060.53" + + +

All Google Chrome users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/google-chrome-103.0.5060.53" + + +

All Microsoft Edge users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/chromium-103.0.5060.53" + + +

All QtWebEngine users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-qt/qtwebengine-5.15.5_p20220618" + +
+ + CVE-2021-4052 + CVE-2021-4053 + CVE-2021-4054 + CVE-2021-4055 + CVE-2021-4056 + CVE-2021-4057 + CVE-2021-4058 + CVE-2021-4059 + CVE-2021-4061 + CVE-2021-4062 + CVE-2021-4063 + CVE-2021-4064 + CVE-2021-4065 + CVE-2021-4066 + CVE-2021-4067 + CVE-2021-4068 + CVE-2021-4078 + CVE-2021-4079 + CVE-2021-30551 + CVE-2022-0789 + CVE-2022-0790 + CVE-2022-0791 + CVE-2022-0792 + CVE-2022-0793 + CVE-2022-0794 + CVE-2022-0795 + CVE-2022-0796 + CVE-2022-0797 + CVE-2022-0798 + CVE-2022-0799 + CVE-2022-0800 + CVE-2022-0801 + CVE-2022-0802 + CVE-2022-0803 + CVE-2022-0804 + CVE-2022-0805 + CVE-2022-0806 + CVE-2022-0807 + CVE-2022-0808 + CVE-2022-0809 + CVE-2022-0971 + CVE-2022-0972 + CVE-2022-0973 + CVE-2022-0974 + CVE-2022-0975 + CVE-2022-0976 + CVE-2022-0977 + CVE-2022-0978 + CVE-2022-0979 + CVE-2022-0980 + CVE-2022-1096 + CVE-2022-1125 + CVE-2022-1127 + CVE-2022-1128 + CVE-2022-1129 + CVE-2022-1130 + CVE-2022-1131 + CVE-2022-1132 + CVE-2022-1133 + CVE-2022-1134 + CVE-2022-1135 + CVE-2022-1136 + CVE-2022-1137 + CVE-2022-1138 + CVE-2022-1139 + CVE-2022-1141 + CVE-2022-1142 + CVE-2022-1143 + CVE-2022-1144 + CVE-2022-1145 + CVE-2022-1146 + CVE-2022-1232 + CVE-2022-1305 + CVE-2022-1306 + CVE-2022-1307 + CVE-2022-1308 + CVE-2022-1309 + CVE-2022-1310 + CVE-2022-1311 + CVE-2022-1312 + CVE-2022-1313 + CVE-2022-1314 + CVE-2022-1364 + CVE-2022-1477 + CVE-2022-1478 + CVE-2022-1479 + CVE-2022-1480 + CVE-2022-1481 + CVE-2022-1482 + CVE-2022-1483 + CVE-2022-1484 + CVE-2022-1485 + CVE-2022-1486 + CVE-2022-1487 + CVE-2022-1488 + CVE-2022-1489 + CVE-2022-1490 + CVE-2022-1491 + CVE-2022-1492 + CVE-2022-1493 + CVE-2022-1494 + CVE-2022-1495 + CVE-2022-1496 + CVE-2022-1497 + CVE-2022-1498 + CVE-2022-1499 + CVE-2022-1500 + CVE-2022-1501 + CVE-2022-1633 + CVE-2022-1634 + CVE-2022-1635 + CVE-2022-1636 + CVE-2022-1637 + CVE-2022-1639 + CVE-2022-1640 + CVE-2022-1641 + CVE-2022-1853 + CVE-2022-1854 + CVE-2022-1855 + CVE-2022-1856 + CVE-2022-1857 + CVE-2022-1858 + CVE-2022-1859 + CVE-2022-1860 + CVE-2022-1861 + CVE-2022-1862 + CVE-2022-1863 + CVE-2022-1864 + CVE-2022-1865 + CVE-2022-1866 + CVE-2022-1867 + CVE-2022-1868 + CVE-2022-1869 + CVE-2022-1870 + CVE-2022-1871 + CVE-2022-1872 + CVE-2022-1873 + CVE-2022-1874 + CVE-2022-1875 + CVE-2022-1876 + CVE-2022-2007 + CVE-2022-2010 + CVE-2022-2011 + CVE-2022-2156 + CVE-2022-2157 + CVE-2022-2158 + CVE-2022-2160 + CVE-2022-2161 + CVE-2022-2162 + CVE-2022-2163 + CVE-2022-2164 + CVE-2022-2165 + CVE-2022-22021 + CVE-2022-24475 + CVE-2022-24523 + CVE-2022-26891 + CVE-2022-26894 + CVE-2022-26895 + CVE-2022-26900 + CVE-2022-26905 + CVE-2022-26908 + CVE-2022-26909 + CVE-2022-26912 + CVE-2022-29144 + CVE-2022-29146 + CVE-2022-29147 + CVE-2022-30127 + CVE-2022-30128 + CVE-2022-30192 + CVE-2022-33638 + CVE-2022-33639 + + ajak + sam +
\ No newline at end of file -- cgit v1.2.3-65-gdbad