Описание
ELSA-2026-18480: linux-sgx security update (IMPORTANT)
[2.26-7]
- Fix pccs npm security flaws
[2.26-6]
- Port to pycryptography and pyasn1 and make keyring optional
[2.26-5]
- Sync specfile changes from Fedora
[2.26-4]
- Drop sgx-mpa dep from sgx-pccs
[2.26-3]
- Add scriptlets for PCCS
[2.26-2]
- Enable pccsadmin everywhere
[2.26-1]
- Update to SGX 2.26 / DCAP 1.23, adding PCCS service
[2.25-7]
- Trigger udev to set perms on /dev/sgx_provision
Обновленные пакеты
Oracle Linux 10
Oracle Linux x86_64
sgx-common
2.26-7.el10
sgx-libs
2.26-7.el10
sgx-mpa
2.26-7.el10
sgx-pccs
2.26-7.el10
sgx-pccs-admin
2.26-7.el10
sgx-pckid-tool
2.26-7.el10
tdx-qgs
2.26-7.el10
Ссылки на источники
Связанные уязвимости
ELSA-2026-18868: linux-sgx security update (IMPORTANT)
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwriting their original behavior. This issue is patched on 4.17.23