Re: Critical information about security vulnerabilities in LFS and BLFS (Dated 2025-05-21)
"\"Douglas R. Reno\"" ([email protected] via lfs-support Mailing List) <[email protected]> Wed, 28 May 2025 11:40:03 -0500
| Newsgroups | gmane.linux.lfs.support |
|---|---|
| Message-ID | <[email protected]> |
On 5/21/25 10:27 AM, Rainer Fiebig ([email protected] via lfs-support Mailing List) wrote: > Am 21.05.25 um 09:12 schrieb "Douglas R. Reno" > ([email protected] via lfs-support Mailing List): >> Good morning folks (it counts as morning here, just hit 12:15am as I am >> writing this :) )! >> >> There have been many important security vulnerability fixes since the >> last email. The security updates this particular cycle have been very >> challenging to work with so far, not only because of personal stuff with >> me (hardware failures causing backlogs combined with my university >> classes the last two weeks) but also dealing with regressions/problems >> from a variety of security updates (including WebKit, Qt6, expat, >> libarchive, and QtWebEngine). These issues will be mentioned throughout >> the descriptions of the updates. The security updates in this email >> require special care, and many of them need to be applied to all of your >> systems immediately to protect them due to their severity and impacts. >> Please treat the issues described in this email as **urgent**. >> >> Before we go over the updates though, I would like to personally thank >> Joe Locash, Rainer Fiebig, Marty Jack, and Zeckma for their help in >> collecting security information, fixing bugs in updates, and >> disseminating security information. Joe has personally reached out to me >> a few times to let me know about issues such as libsoup and giflib, and >> has filed tickets for other ones that I was able to get into the book in >> time for this round of security advisories. Rainer has inquired about >> the advisories a couple of times which has helped me describe some of >> the issues that have come up, and Zeckma assisted me with getting a few >> updates in (Firefox/Thunderbird) to make things easier for this set of >> advisories. Joe also provided me with a helpful fix for LibreOffice due >> to OpenJDK, which saved me potentially several rebuilds of LibreOffice >> trying to fix the issue. Marty also provided me with an extremely >> helpful patch to fix issues with LibreOffice and poppler. Thank you all >> so much for your help, without it this would've been much tougher to >> take care of. >> >> Another important thing to mention is that **all** users who have >> make-ca installed need to make sure that they are on make-ca-1.16 to >> prevent issues with obtaining updated security certificates from >> Mozilla. Mozilla recently changed the domain that we get the >> certificates from hg.mozilla.org to hg-edge.mozilla.org, and in addition >> to the domain, also changed the organization that signs the certificate >> for the new domain. Because of that, previous versions of make-ca will >> no longer be able to contact Mozilla's servers to download the security >> certificates. In make-ca-1.16 we fixed this by shipping the correct root >> certificate to contact hg-edge.mozilla.org, and corrected the domain name. >> >> Users who are building stable LFS will have noticed that expat-2.6.4 is >> no longer available. Please download 2.7.1 instead, as 2.6.4 was pulled >> upstream due to security vulnerabilities. It has been tested on BLFS >> 12.3 systems and is confirmed to work well. >> >> This email will cover the following packages: >> >> - libxslt >> >> - PHP >> >> - Expat (LFS) >> >> - WebKitGTK >> >> - libarchive >> >> - Exim >> >> - Mercurial >> >> - Qt6 >> >> - QtWebEngine >> >> - lxml (Python Module) >> >> - libxml2 >> >> - Exempi >> >> - c-ares >> >> - Perl (LFS) >> >> - Python (LFS and BLFS) >> >> - xz (LFS) >> >> - Yelp >> >> - libsoup3 >> >> - libsoup2 >> >> - giflib >> >> - Epiphany >> >> - ghostscript >> >> - gstreamer >> >> - LibreOffice >> >> - PostgreSQL >> >> - intel-microcode >> >> - Screen >> >> - OpenJDK >> >> - Gimp >> >> - Spidermonkey >> >> - Firefox >> >> - Thunderbird >> >> **libxslt**: We'll begin with libxslt. This security update has been >> rated as High. Two security vulnerabilities were fixed here which could >> allow for arbitrary code execution, as well as crashes when processing >> XSL documents. Both vulnerabilities are due to use-after-free bugs. One >> of them happens when processing XPath context nodes, because an XPath >> context node can be modified but never restored when using nested XPath >> evaluations. Applications which use the xsltNumberFormatGetValue, >> xsltEvalXPathPredicate, xsltEvalXPathStringNs, and >> xsltComputeSortResultInternal functions may be impacted. The other >> vulnerability happens in the xsltGetInheritedNsList function, and is >> related to the exclusion of result prefixes. Users who have libxslt >> installed should update to libxslt-1.1.43, especially since these >> vulnerabilities can theoretically be triggered through XHTML pages if >> you are using QtWebEngine as configured in the book. >> >> **PHP**: This security update has been rated as Medium. A total of seven >> vulnerabilities were fixed that could cause crashes, arbitrary code >> execution, unauthorized HTTP redirects, authentication bypasses, remote >> system crashes, and for invalid HTTP headers to be processed. The >> vulnerabilities exist in the Streams, libxml, and Core components within >> PHP. **ALL** users who have PHP installed and use it in the context of a >> web application are encouraged to update to at least PHP 8.4.5 to fix >> these vulnerabilities. >> >> **Expat (LFS)**: This security update has been rated as High. A security >> vulnerability was fixed that could result in a crash from chaining a >> large number of entities. The vulnerability is caused by a stack >> overflow, and upstream resolved it by fixing the usage of recursion for >> general entities in character data and attribute data, as well as for >> parameter entities. The crash is unfortunately very easy to trigger. >> This update was a little complex to put in though, as the initial >> version that it was fixed in (2.7.0) introduced a major regression where >> any application that called the XML_GetCurrentByteCount, >> XML_GetCurrentByteIndex, XML_GetCurrentColumnNumber, >> XML_GetCurrentLineNumber, and the XML_GetInputContext functions to >> immediately crash. It was originally discovered in the XML::Parser perl >> module's test suite, and we immediately brought it to upstream at >> https://github.com/cpan-authors/XML-Parser/issues/104 as soon as it was >> discovered. We recommend that all users who have Expat installed update >> to Expat 2.7.1 as soon as possible because of how easy the crash is to >> trigger, and how many applications use Expat for XML parsing behind the >> scenes. >> >> **WebKitGTK**: This security update has been rated as Critical. Sixteen >> security vulnerabilities were fixed that could result in unexpected >> process crashes, cross-origin data exfiltration, memory corruption, >> cross-site scripting attacks, type confusion (note that this only >> affects ARM architectures), and sandbox escapes. The sandbox escape >> vulnerability is known to be exploited in the wild. This update took a >> long time because of issues that cropped up with 32-bit systems, and >> 64-bit systems with less than 16GB of RAM. CMake defaults to using -O3 >> for the optimization level when you do a Release build, and one of the >> automatically generated files that WebKit creates is extremely large. It >> was discovered that systems with less than 16GB of RAM could not build >> WebKitGTK-2.48.0 or later without manually decreasing the optimization >> level, which we now cover in the Important note in the WebKitGTK page >> prior to build instructions. This unfortunately caused a significant >> delay as it took over a dozen attempts before I was able to come up with >> a workable solution. Rahul, Thomas, and Xi also took a stab at the issue >> at points, as well as Ken - thank you all! Because of the variety of >> impacts here as well as the fact that the sandbox escape is known to be >> exploited in the wild, all users who have WebKitGTK installed should >> update to 2.48.2 immediately. >> >> **libarchive**: This security update has been rated as Medium. Three >> security vulnerabilities were fixed here that could allow for denial of >> service (application crashes) or memory corruption when processing ZIP >> or TAR archives. The ZIP vulnerability exists in the 'bsdunzip' utility, >> and there is a public proof of concept exploit available - however, note >> that the worst impact is a crash. The TAR issues are both due to >> heap-based buffer overreads, and can occur when handling truncation in >> the middle of GNU long linknames, and when checking strftime return >> values. The vulnerabilities were fixed in 3.7.8, but a major regression >> was discovered in 3.7.8 and we thus recommend updating to >> libarchive-3.7.9 instead. >> >> **Exim**: This security update has been rated as High. A security >> vulnerability was fixed that could allow users with command line access >> to the server to obtain privilege escalation to root. The issue is >> caused by a use-after-free issue, and in BLFS systems, can occur before >> exim fully drops privileges to the 'exim' user depending on timing. If >> you have Exim installed on your system, you should update to Exim 4.98.2. >> >> **Mercurial**: This security vulnerability has been rated as Medium, >> because the default BLFS configuration is not impacted. If you are not >> using the 'hgweb' program (which is not part of the standard BLFS >> configuration), you may safely skip this update. If you do use the >> 'hgweb' program, it is vulnerable to cross-site scripting attacks. The >> vulnerability allows attackers to forge a link that will execute >> JavaScript code in the victim's browser, but note that most WSGI >> implementations will throw a HTTP 500 error instead of allowing the >> exploit to succeed. Still though, if you use the 'hgweb' functionality >> from Mercurial, you should update to Mercurial 7.0.1. >> >> **Qt6**: This security update has been rated as Low. A security >> vulnerability has been fixed that could allow for a heap buffer overflow >> when passing an incorrectly formatted Markdown file to an application >> that utilizes QTextMarkdownImporter. The only known impacts at this time >> are application crashes. There are two approaches to fixing this >> vulnerability. One way is to apply the official Qt patch to your system >> if you have Qt 6.8.x installed. That patch can be found at >> https://download.qt.io/official_releases/qt/6.8/CVE-2025-3512-qtbase-6.8.diff, >> but note that the BLFS team has not tested this approach (though there >> is a very very low chance that it doesn't work). The other option would >> be to upgrade your system to Qt 6.9.0. This involves a lot of risk, and >> can be complex. The risk being that a lot of private API that >> applications were depending on was changed in Qt 6.9.0. These issues >> start to crop up in Plasma, libportal, and LXQt (due to a dependency on >> a Plasma component). If you decide to update to Qt 6.9.0, you will need >> to rebuild libportal with the patch in the development book to fix usage >> of private API, as well as rebuild Plasma with the instructions in the >> development book again because of private API usage. If you use LXQt and >> have only installed the minimal set of KDE components necessary to use >> it, you will need to rebuild layer-shell-qt also because of private API >> usage. After updating Qt you will also need to rebuild anything that >> installs files in /opt/qt6 - in BLFS that includes qca and qcoro. Most >> users will very likely not be impacted by this vulnerability, so the >> risk in skipping this update is Low. However, if you do decide to update >> to Qt 6.9.0, please keep the above information in mind. >> >> **QtWebEngine**: This security update has been rated as Critical. In >> QtWebEngine-6.9.0, fifteen security vulnerabilities were fixed that >> could allow for sensitive system data exfiltration, user interface >> spoofing, remote code execution, arbitrary code execution, and sandbox >> escapes. The vulnerabilities are in a variety of components in the >> bundled copy of Chromium, including GPU, 7-zip, Network, V8, Browser, >> UI, DevTools, Media, Media Stream, PDFium, WebRTC, and Inspector. The >> WebRTC vulnerability is known to be exploited in the wild, and is a >> sandbox escape. It is the exact same vulnerability fixed in WebKitGTK, >> and we thus recommend that all users update this package immediately. >> However, there was a regression discovered after the release of >> QtWebEngine-6.9.0, where GPU acceleration was broken. This was another >> one of those challenging bugs to fully resolve in BLFS, since there were >> many moving parts involved. We've developed a patch with commits from >> upstream that fixes the issue, however in addition to applying the patch >> users must update Falkon to the latest version as well. That has been >> tested to work on a BLFS 12.3 system though without modifications. All >> users with QtWebEngine should update to QtWebEngine 6.9.0 with the patch >> immediately, and then rebuild Falkon to ensure that GPU acceleration >> continues to function correctly. >> >> **lxml (Python Module)**: This security update has been rated as High. >> In lxml-5.4.0, the bundled copies of libxml2 and libxslt were updated to >> fix five security vulnerabilities. The vulnerabilities allow for >> arbitrary code execution and crashes when processing crafted XML and >> XSLT documents. The issues occur due to heap-based buffer underreads, >> stack buffer overflows, out of bounds memory accesses, and >> use-after-free issues. Users who have the lxml python module installed >> should update to lxml-5.4.0. >> >> **libxml2**: This security update has been rated as High. In >> libxml2-2.14.2 (and 2.13.8), two security vulnerabilities were fixed >> that could result in a denial of service or arbitrary code execution >> when processing XML documents. One of the issues occurs in the >> xmlSchemalDCFillNodeTables function, and is due to a heap-based buffer >> under read. To exploit that vulnerability, an attacker must validate the >> XML document against an XML schema with certain identity constraints >> (although a crafted XML schema can be used as well). The other >> vulnerability is in the Python API, and it causes an out of bounds >> memory access due to an incorrect return value when using the >> xmlPythonFileRead and xmlPythonFileReadRaw functions. The issue occurs >> because of a difference in bytes and characters. This update brings >> something that requires special care. libxml2-2.14 is ABI incompatible >> with libxml2-2.13, and many packages on the system must be recompiled in >> order to fix the vulnerability. If you update to libxml2-2.14, you must >> also update libxkbcommon and localsearch to fix critical runtime issues >> that libxml2-2.14 causes in those packages. As a result, we recommend >> that users stay on the libxml2-2.13 series and update to 2.13.8 instead >> of upgrading to 2.14 on an existing system. >> >> **Exempi**: This security update has been rated as Medium. Before we go >> any further on this one, I want to note that even though the >> vulnerabilities look severe here, they are rated as Medium by upstream >> because they are challenging to exploit and require the usage of >> advanced XMP features. In Exempi-2.6.6, five security vulnerabilities >> were fixed in the bundled Adobe XML Toolkit SDK that could allow for >> out-of-bounds reads. The impacts include denial of service (application >> crashes), and information disclosure of sensitive memory when processing >> crafted XMP metadata. Updating to Exempi-2.6.6 is recommended if you >> manipulate files with XMP metadata. >> >> **c-ares**: This security update has been rated as High. A security >> vulnerability was fixed that could allow for a crash when processing DNS >> queries where a DNS Cookie Failure occurs, when an upstream server does >> not properly support EDNS, or potentially on TCP queries if the remote >> server closed the connection immediately after a response. The crash >> occurs due to a use-after-free issue in the read_answers() function, and >> is theoretically exploitable by remote attackers if the attacker can >> flood your system with ICMP UNREACHABLE packets - but in order for this >> to happen, the attackers must have control over the upstream nameserver. >> The vulnerability has been rated as High upstream due to the fact that >> it's attack vector is Network, and the impact is a remotely exploitable >> crash, but note that the attack complexity is High. Users who have >> c-ares installed should update to c-ares-1.34.5. >> >> **Perl (LFS)**: This security update has been rated as High. A security >> vulnerability was fixed that could allow for a denial of service or >> arbitrary code execution when transliterating non-ASCII bytes. The issue >> is caused by a heap buffer overflow, and a subsequent out of bounds >> write. A simple one-line reproducer is available that demonstrates a >> crash caused by the vulnerability. Users should update to Perl 5.40.2. >> If you are on an older version of LFS which has one of Perl 5.38, 5.36, >> or 5.34 - the Perl developers have put out new releases for those lines! >> You'll want to update to 5.38.4, 5.36.3, or 5.34.3. >> >> **Python (LFS and BLFS): This security update has been rated as Medium. >> In Python-3.13.3, two security vulnerabilities were fixed that could >> allow for unbounded memory usage (causing a denial of service by >> consuming all of the RAM on your system), and for email header spoofing. >> However, after the release of 3.13.3, an additional security >> vulnerability was discovered that can allow for a crash when using the >> unicode_escape encoding or an error handler when decoding bytes with the >> bytes.decode() function. The unbounded memory usage issue occurs while >> writing temporary files with the >> tempfile.SpooledTemporaryFile.writelines() function, as the function >> only checks whether it should roll over after the entire line's iterator >> is exhausted. The email header spoofing vulnerability occurs when using >> RFC2047 encoding and using the as_bytes function with the policy=default >> behavior. Users should update to Python 3.13.3 with the security fixes >> patch that we implemented earlier for the unicode_escape vulnerability >> (thank you to Joe Locash for filing a ticket in BLFS for it). >> >> **xz (LFS)**: This security update has been rated as High. A security >> vulnerability was resolved that could allow for invalid input when >> decompressing a XZ file to cause a denial of service (crash) or >> arbitrary code execution. The issue is caused by a heap use after free, >> but it can also write to an address based on the null pointer plus an >> offset. This can be used to inject bytes into memory. Applications and >> libraries which use the lzma_stream_decoder_mt function are impacted, >> but note that the vulnerability only gets triggered when decompressing >> crafted files. That being said though, all users are recommended to >> update to xz-5.8.1 as soon as possible especially if you decompress >> unknown/untrusted xz files. >> >> **yelp**: This security update has been rated as High. This one is a bit >> special, as it really should be rated as Critical. A security >> vulnerability was found in Yelp-42.2 that allows for help documents to >> execute arbitrary JavaScript and also read arbitrary files on the disk. >> Upstream has **not** released a patched version of yelp/yelp-xsl to >> resolve the problem, but the BLFS team has adopted some patches from >> upstream to resolve it ourselves. The patches resolve the issue by >> implementing a Content Security Policy through some calls to WebKit, >> which prevent JavaScript code from being executed. There is a public >> writeup and exploit available, and it shows just how dangerous this >> vulnerability is. The exploit demonstrates reading a user's SSH private >> key via a crafted help document, and exfiltrating it to another system. >> Because of that, **ALL** BLFS USERS WHO HAVE YELP INSTALLED SHOULD APPLY >> THE PATCHES AS SOON AS POSSIBLE. Note that patches will need to be >> applied to both yelp-xsl and yelp for the mitigation of the >> vulnerability to be successful. >> >> **libsoup3*: This security update has been rated as Critical. In >> libsoup3, ten security vulnerabilities were fixed that could allow for >> remotely exploitable crashes, remote code execution, and memory >> corruption. The vulnerabilities happen in a variety of different >> functions inside of libsoup3, including append_param_quoted(), >> sniff_unknown(), sniff_feed_or_html(), soup_headers_parse_request(), >> sniff_mp4(), soup_auth_digest_authenticate(), and >> soup_message_headers_get_content_disposition(). These functions are used >> in many programs that use libsoup3, and the issues occur due to a >> variety of problems including integer overflows, segmentation faults, >> heap buffer over reads, out of bounds reads, NULL pointer dereferences, >> and double frees. Unfortunately there are many more vulnerabilities in >> libsoup3 which have been reported upstream but have not been properly >> fixed at this time, but please keep an eye on the security advisories to >> be informed on when more are fixed. All users who have libsoup3 should >> update to 3.6.5 as soon as possible. Special thanks goes to Joe Locash >> for reporting the initial list and to both Joe and Xi for helping keep >> track of the new issues. >> >> **libsoup2**: This security update has been rated as Critical. In >> libsoup2, fourteen security vulnerabilities were fixed that could allow >> for remotely exploitable crashes, remote code execution, HTTP Request >> Smuggling, and memory corruption. These are extremely similar to the >> vulnerabilities fixed in libsoup3, but with some that are also specific >> to libsoup2. Because libsoup2 is no longer maintained upstream, and the >> packages which use it are abandoned, it has been removed from the >> development books and will not be available in BLFS 12.4. That has >> included archiving AbiWord and libgdata as they are both abandoned. >> However, we have created a final patch to fix the fourteen security >> vulnerabilities, and the patch can be found at >> https://linuxfromscratch.org/patches/downloads/libsoup/libsoup-2.74.3-security_fixes-1.patch. >> Users who have libsoup2 installed should discontinue use and migrate to >> libsoup3 where possible, but the patch that we have created and tested >> passes the test suite cleanly and does not break libgdata or AbiWord. >> >> **giflib**: This security update has been rated as High. Several >> security vulnerabilities were discovered in giflib-5.2.2, but only one >> of them has a functional patch. That vulnerability has been assigned >> four different individual CVEs, and it causes a buffer overflow in the >> gif2rgb utility. Upon the issue being reported to us, we adopted a patch >> from OpenMandriva which fixes this particular vulnerability, but please >> stay tuned to the security advisories for future updates which fix other >> issues in giflib that are currently known (and reported to upstream), >> but have not been fixed at this time. Rebuilding giflib with the patch >> now implemented in the development books is recommended. >> >> **Epiphany**: This security update has been rated as High. In >> Epiphany-48.1, a security vulnerability was fixed that allows websites >> to trigger URL handlers with no user interaction or warning. If the >> handler application that is called is vulnerable to other issues, remote >> code execution would be possible under the user's current context. >> Before 48.1, the browser did not prevent external URL handler >> applications from launching without a user's permission, and also did >> not warn users about the applications opening. As an example, this could >> be chained with the Yelp vulnerability to trigger Yelp into launching a >> malicious Help document from a server. However, two regressions were >> introduced with this update which cause crashes when downloading opened >> files and opening Incognito windows, so we recommend that all users >> update to Epiphany 48.3 instead if they have Epiphany installed. >> >> **ghostscript**: This security update has been rated as Critical. In >> ghostscript-10.05.0, nine security vulnerabilities were fixed that could >> result in remote code execution or arbitrary file accesses. The >> arbitrary file execution vulnerability occurs due to truncated paths >> with invalid UTF-8 characters, but the remote code execution >> vulnerabilities occur due to buffer overflows in various contexts, >> including processing PDF files, serializing fonts (common when >> printing!), utilizing BJ10V, DOCXWRITE TXTWRITE, and NPDL devices, and >> when converting glyphs to Unicode. All users who have ghostscript >> installed are encouraged to update to ghostscript-10.05.0 or later as >> soon as possible, especially if they use a printer or use ghostscript >> for PDF manipulation. >> >> **gstreamer**: This security update has been rated as High. In >> gst-plugins-bad-1.26.1, a security vulnerability was fixed that can >> allow for crashes or remote code execution (in the context of a web >> browser) when processing malformed streams in a video file using the >> H.265 codec. The issue is caused by a stack buffer overflow that occurs >> when processing slice headers. The CVE number is still reserved, but >> some basic information can be found upstream at >> https://gstreamer.freedesktop.org/security/sa-2025-0001.html. All users >> who have the gstreamer stack installed should update to update the stack >> to 1.26.1 as soon as possible. >> >> **LibreOffice**: This security update has been rated as Critical. Note >> that this vulnerability only impacts users who use LibreOffice to open >> or modify PDF documents. In LibreOffice-25.2.2.2, a security >> vulnerability was fixed that allows for PDF signature forgery when using >> the adbe.pkcs7.sha1 SubFilter. The bug causes invalid signatures to be >> accepted as valid, and NVD has rated it as Critical because it meets >> criteria including "Improper Verification of Cryptographic Signature" >> and "PDF Signature Spoofing by Improper Validation". Users who use >> LibreOffice for reading or modifying PDFs should update to >> LibreOffice-25.2.2.2 as soon as possible, especially as this could allow >> for phishing attacks. >> >> **PostgreSQL**: This security update has been rated as Medium. In >> PostgreSQL-17.5, a security vulnerability was fixed that could allow for >> a database input provider to achieve a temporary denial of service on >> any platform where a 1-byte over-read can trigger process termination. >> The issue occurs when performing GB18030 encoding validation, and it's >> classified as a buffer over-read. Unfortunately it affects libpq as well >> as the database server, so client applications can also crash as well as >> the database server itself. Note that text must fail validation for this >> vulnerability to get exploited. Users who have PostgreSQL installed >> should consider upgrading to PostgreSQL 17.5 depending on the context in >> which they use the database server (or client applications), such as >> when processing untrusted input. If you are just using PostgreSQL as a >> build dependency for something else, there is no need to update. If you >> are on older versions of BLFS that use older versions of PostgreSQL, >> versions 16.9, 15.13, 14.18, and 13.21 have also been made available! >> >> **intel-microcode**: This security update has been rated as Medium. In >> intel-microcode-20250512, eight processor level security issues were >> addressed. Six of the vulnerabilities allow for information disclosure, >> and two allow for denial of service. These vulnerabilities apply to a >> variety of different processors, including the 8th, 9th, 10th, 11th, >> 12th, 13th, and 14th generation of Intel Core CPUs, the Atom P6000 >> family, various Celeron and Pentium CPUs, the Core Ultra family, the >> Intel Xeon Scalable CPU family, the Xeon E processor family, the Xeon 6 >> processor family, and the Xeon W processor family. Users with Intel CPUs >> are encouraged to review the security advisory to determine if their CPU >> is affected, and update the microcode if they are. In the future, we may >> add fwupd which may allow users to install BIOS updates to fix these >> issues instead, depending on if their hardware is supported by LVFS. >> >> **Screen**: This security update has been rated as High. In >> Screen-5.0.1, five security vulnerabilities were fixed that could allow >> for users to reliably escalate privileges to root, for allowing >> attackers to determine if files exist, for TTY hijacking while attaching >> to a multi-user session, for race conditions when sending signals, and >> for PTYs to be created world-writable. A serious buffer overflow bug >> caused by a bad strncpy() was also fixed in this release. The default >> configuration in BLFS is to install Screen as setuid-root, and thus all >> systems with Screen installed are impacted by these vulnerabilities. >> Some of the vulnerabilities date back to around 2005. If you have Screen >> installed please update to Screen-5.0.1 immediately. More details about >> this set of vulnerabilities can be found at >> https://seclists.org/oss-sec/2025/q2/117 >> >> **OpenJDK**: This security update has been rated as High. In >> OpenJDK-24.0.1, three security vulnerabilities were fixed that could >> allow for remote code execution, arbitrary code execution, and >> unauthorized data modification. No user interaction, nor privileges, are >> required to exploit these vulnerabilities. The vulnerabilities are in >> the JSSE, 2D, and Compiler components. The JSSE and 2D vulnerabilities >> impact all versions of Java after JDK 8, while the Compiler >> vulnerability only impacts JDK 21 and higher. All users who have Java >> installed should update to OpenJDK-24.0.1, especially if you are running >> a networked application. If you update to OpenJDK-24.0.1, please update >> to fop-2.11 at the same time and update to Libreoffice-25.2.3.2 to work >> around issues with the removal of the Java Security Manager API. >> >> **Gimp**: This security update has been rated as High. In Gimp-3.0.4, a >> security vulnerability was fixed that could allow for remote code >> execution when processing a crafted .ICO file. The vulnerability is >> caused by an integer overflow. No CVE has been assigned yet, but there >> is a Zero Day Initiative identifier assigned to the vulnerability. There >> is a proof of concept exploit available that corrupts Gimp's internal >> state. Given that it's a remote code execution vulnerability, we've >> decided to go ahead with filing an advisory for it even though the only >> information available is the bug report and the fix (which has been >> officially released). All users who have Gimp installed that may >> read/modify .ICO files should update to Gimp-3.0.4, but note that you >> must update to babl-0.1.114 and gegl-0.4.62 at the same time. Users who >> are not reading/modifying .ICO files can ignore this security update. >> >> **Spidermonkey**: This security update has been rated as Critical. If >> there were a higher rating than Critical, I would assign it to this and >> the two updates following this one. At the Vancouver Pwn2Own conference, >> two critical security vulnerabilities were demonstrated where attackers >> were able to read and write out of bounds memory through executing >> malicious JavaScript. This allows for JavaScript manipulation as well as >> remote code execution. All users who have SpiderMonkey installed >> **urgently** need to install Spidermonkey-128.10.1. Do NOT delay with >> this update, please update immediately! >> >> **Firefox**: This security update has been rated as Critical. In >> Firefox-128.10.1 (and previous versions dating back to 128.9.0 which was >> the last time an advisory was filed), a total of nine security >> vulnerabilities were fixed. These vulnerabilities allow for remote code >> execution, URL bar spoofing, sandbox escapes, and unsafe attribute >> access (leading to out of bounds memory access and memory corruption). >> Most of these vulnerabilities are exploitable via standard web browsing. >> Two of the remote code execution vulnerabilities are known to be >> exploited in the wild. At the Vancouver Pwn2Own conference, two critical >> security vulnerabilities were demonstrated where attackers were able to >> read and write out of bounds memory through executing malicious >> JavaScript. This allows for JavaScript manipulation as well as remote >> code execution. **ALL USERS WHO HAVE FIREFOX INSTALLED MUST UPDATE >> IMMEDIATELY TO PROTECT THEIR SYSTEMS!!** >> >> **Thunderbird**: This security update has been rated as Critical. Note >> the several additional critical impacts in addition to the remote code >> execution issues shared by Spidermonkey and Firefox. In >> Thunderbird-128.10.2esr (as well as versions dating back to 128.9.1), >> eighteen security vulnerabilities were fixed. These vulnerabilities >> allow for remote code execution, URL bar spoofing, arbitrary code >> execution, exfiltration of credentials to remote attackers via >> compromised emails and attachments, information disclosure of a >> directory listing of the contents of /tmp, UI misrepresentation of >> attachment URLs (leading to possible phishing attacks), remotely >> exploitable crashes, sandbox escapes, unauthorized and unsolicited file >> downloads to arbitrary locations on a user's hard disk, JavaScript >> execution via malicious PDF attachments, and tracking links in >> attachments bypassing remote content blocking. This may be one of the >> most serious and dangerous set of vulnerabilities I have seen in my >> entire 11+ years working on LFS/BLFS. Note that Thunderbird is also >> impacted by the same remote code execution issues fixed in Spidermonkey >> and Firefox. **ALL USERS WHO HAVE THUNDERBIRD INSTALLED MUST UPDATE >> IMMEDIATELY TO PROTECT THEIR SYSTEMS!!** >> >> >> This was quite the long set of security updates, and there's a lot to >> unpack here. I know I've said so several times, but I must urge everyone >> to take these updates seriously and update as soon as humanly possible >> to protect your systems (as well as your data and credentials, >> especially in the case of Thunderbird/Firefox/Spidermonkey). In all of >> my years working on the books, this is probably the largest set of >> significant vulnerabilities I have ever seen, in a very large sprawl of >> packages. Please take these issues seriously, and do not delay with >> updating your systems. >> >> - Douglas Reno >> > Thanks a lot, Doug, for this tremendous and important piece of work and > the huge amount of spare time this must have cost you! > > I'm still reeling a bit from this avalanche of updates and given all the > text one had to digest, one thing came to my mind: that it might be > better to put the most important stuff, the instruction of what to do, > rather at the beginning of a section instead of at the end. Examples: > > **libxslt**: Update to libxslt-1.1.43. This security update has been > rated as High. ... > > **libsoup3*: Update to 3.6.5. This security update has been rated as > Critical. ... > > I think this would make it easier to see what needs to be done, > especially when confronted with a mountain of updates like this time. > > Having updated _one_ system, I'm wondering whether I will ever recover > from this. At least I need a break now... ;) > > Thank you very much again! Fine work and great service! > > Rainer > Thank you so much for the feedback and the kind words! I was adjusting the template a bit for this one and I think it'll be good to make that change as well. It definitely will make it easier for users to parse :) - Doug -- http://lists.linuxfromscratch.org/sympa/info/lfs-support Unsubscribe: See the above information page