GSA-6393-1: Linux Security Update
What: A critical Linux kernel security update is now available.
Who: Gnoppix Security issued the advisory for Gnoppix 23/25 and Gnoppix 25.
When: The update addresses multiple vulnerabilities discovered in the Linux kernel.
Why: These flaws could allow attackers to cause system crashes or execute malicious code.
Affected Systems
- Gnoppix 23/25 (stable)
- Gnoppix 25 (stable)
Technical Details
The update covers issues within the netfilter subsystem. Vulnerabilities could lead to a denial of service or privilege escalation.
Key Vulnerabilities Fixed
- Missing upper bound check in netfilter netdev hooks.
- Buffer over-read in the calipso network labeling module.
- Use-after-free in the io_uring asynchronous I/O framework.
Action Required
Apply the updated packages immediately. Reboot the system after installation to activate the new kernel.
Gnoppix Security recommends immediate patching. Exploitation of these vulnerabilities is possible. A system reboot is mandatory. - Please update your systems.