2026年8月27日木曜日

27日 木曜日、先負

+ RHSA-2026:60305 Important: go-toolset:rhel8 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:60305
CVE-2026-33818
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:59821 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:59821
CVE-2026-52924
CVE-2026-63886
CVE-2026-63913
CVE-2026-64189
CVE-2026-64191
CVE-2026-64276
CVE-2026-64277
CVE-2026-64320

+ RHSA-2026:60304 Important: golang security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:60304
CVE-2026-33818
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:60224 Moderate: pam security update
https://access.redhat.com/errata/RHSA-2026:60224
CVE-2026-54411

+ RHSA-2026:60226 Moderate: attr security update
https://access.redhat.com/errata/RHSA-2026:60226
CVE-2026-54371

+ RHSA-2026:59723 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:59723
CVE-2025-68211
CVE-2026-23003
CVE-2026-43114
CVE-2026-52920
CVE-2026-52924
CVE-2026-53131
CVE-2026-53185
CVE-2026-53268
CVE-2026-64189
CVE-2026-64191
CVE-2026-64276
CVE-2026-64277
CVE-2026-74581

+ Google Chrome 153.0.8010.12/.13 released
https://chromereleases.googleblog.com/2026/08/early-stable-update-for-desktop_0935803414.html

+ FreeBSD-SA-26:63.posixshm TOCTOU race in POSIX shared memory large page configuration
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:63.posixshm.asc
CVE-2026-58094

+ FreeBSD-SA-26:62.tty Kernel use-after-free via tty ioctls
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:62.tty.asc
CVE-2026-58093

+ FreeBSD-SA-26:61.openssl Multiple vulnerabilities in OpenSSL
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:61.openssl.asc
CVE-2026-14457
CVE-2026-18798
CVE-2026-54874
CVE-2026-63072
CVE-2026-63073
CVE-2026-63074
CVE-2026-63075
CVE-2026-63076

+ FreeBSD-SA-26:60.ppp Multiple vulnerabilities in ppp(8)
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:60.ppp.asc
CVE-2026-58095
CVE-2026-58096
CVE-2026-58097

+ FreeBSD-SA-26:59.mac_do Unauthorized credential switching
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:59.mac_do.asc
CVE-2026-58092

+ FreeBSD-SA-26:58.sound Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:58.sound.asc
CVE-2026-58091

+ FreeBSD-SA-26:57.unix Use-after-free in unix SOCK_STREAM message handling
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:57.unix.asc
CVE-2026-58090

+ FreeBSD-SA-26:56.hwpmc hwpmc fails to detach PMCs during exec credential transitions
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:56.hwpmc.asc
CVE-2026-58089

+ UPDATE: JVNVU#95772889 OpenSSLにおける秘密鍵のタイミング攻撃に対する問題(OpenSSL Security Advisory [20th January 2025])
https://jvn.jp/vu/JVNVU95772889/index.html

+ UPDATE* JVNVU#90424473 OpenSSLにおける境界外書き込みの脆弱性(OpenSSL Security Advisory [16th October 2024])
https://jvn.jp/vu/JVNVU90424473/index.html

+ UPDATE: JVNVU#94584169 OpenSSLのASN.1 オブジェクト識別子変換における処理時間遅延の問題(Security Advisory [30th May 2023])
https://jvn.jp/vu/JVNVU94584169/index.html

+ UPDATE: JVNVU#94632906 OpenSSLのX.509ポリシー制限の検証における過剰なリソース消費の問題
https://jvn.jp/vu/JVNVU94632906/index.html

+ UPDATE: JVNVU#91213144 OpenSSLに複数の脆弱性
https://jvn.jp/vu/JVNVU91213144/index.html

+ UPDATE: JVNVU#98667810 OpenSSL に複数の脆弱性
https://jvn.jp/vu/JVNVU98667810/index.html

+ JVNVU#92836377 GNU C Libraryにおける複数の脆弱性
https://jvn.jp/vu/JVNVU92836377/index.html

+ JVNVU#96149019 Apache Tomcatにおける複数の脆弱性(2026年8月25日)
https://jvn.jp/vu/JVNVU96149019/index.html

+ JVNVU#96558110 OpenSSLにおける脆弱性に対するアップデート(2026年8月25日)
https://jvn.jp/vu/JVNVU96558110/index.html

+ OpenSSLの脆弱性(CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803)と4.0.2, 3.6.4, 3.5.8, 3.4.7, 3.0.22, 1.1.1zi,1.0.2zrリリース
https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260826/
CVE-2026-14457
CVE-2026-18798
CVE-2026-54874
CVE-2026-63072
CVE-2026-63073
CVE-2026-63074
CVE-2026-63075
CVE-2026-63076
CVE-2026-75803

JVNTA#95077890 SSH接続の安全性を低下させる攻撃手法Terrapin Attackについて
https://jvn.jp/ta/JVNTA95077890/index.html

JVNVU#96423082 Diffie-Hellman鍵交換におけるサービス運用妨害(DoS)の脆弱性
https://jvn.jp/vu/JVNVU96423082/index.html

JVN#67155805 Androidアプリ「マイナポイント」におけるアクセス制限不備の脆弱性
https://jvn.jp/jp/JVN67155805/index.html

JVN#18496672 CorvusSKKにおける複数の脆弱性
https://jvn.jp/jp/JVN18496672/index.html

JVNVU#94434952 Kaltura HTML5 Player Libraryにおける複数の脆弱性
https://jvn.jp/vu/JVNVU94434952/index.html

日経NETWORK 特別リポート
企業を襲うサイバー詐欺の実態
決算調査で判明
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800013/081800106/?ST=nxt_thmit_security

NEWS close-up
AIモデルの他社システム侵入が相次ぐ
OpenAIに続きAnthropicでも発生 AIモデルの「暴走」対策が課題に
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/081800337/?ST=nxt_thmit_security

吉川孝志のマルウエア徹底解剖 第31回
徹底解説 AIはサイバーセキュリティーの何を変え、何を変えなかったのか
https://xtech.nikkei.com/atcl/nxt/column/18/02805/081900032/?ST=nxt_thmit_security

北郷達郎のテクノロジー温故知新
「電脳コイル」から20年、描かれた世界観を実現する最新AIグラスを検証
https://xtech.nikkei.com/atcl/nxt/column/18/02598/081900036/?ST=nxt_thmit_security

2026年8月26日水曜日

26日 水曜日、友引

+ RHSA-2026:59487 Important: gstreamer1-plugins-base security update
https://access.redhat.com/errata/RHSA-2026:59487
CVE-2026-18297

+ RHSA-2026:59241 Important: python-pyasn1 security update
https://access.redhat.com/errata/RHSA-2026:59241
CVE-2026-59886

+ RHSA-2026:59216 Important: nginx:1.24 security update
https://access.redhat.com/errata/RHSA-2026:59216
CVE-2026-56434
CVE-2026-60005

+ RHSA-2026:59179 Important: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:59179
CVE-2026-18295
CVE-2026-18296
CVE-2026-18298
CVE-2026-18299

+ RHSA-2026:59146 Important: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_125_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 security update
https://access.redhat.com/errata/RHSA-2026:59146
CVE-2026-43499
CVE-2026-45984
CVE-2026-46116
CVE-2026-46227

+ RHSA-2026:58898 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:58898
CVE-2026-74934
CVE-2026-74935
CVE-2026-74936
CVE-2026-74939
CVE-2026-74940
CVE-2026-74941
CVE-2026-74942
CVE-2026-74943
CVE-2026-74944
CVE-2026-74945
CVE-2026-74946
CVE-2026-74948
CVE-2026-74949
CVE-2026-74953
CVE-2026-74957
CVE-2026-74959
CVE-2026-74960
CVE-2026-74962
CVE-2026-74963
CVE-2026-74964
CVE-2026-74965
CVE-2026-74967
CVE-2026-74969
CVE-2026-74971
CVE-2026-74972
CVE-2026-74973
CVE-2026-74974
CVE-2026-74976
CVE-2026-74983
CVE-2026-74987
CVE-2026-74990

+ RHSA-2026:58562 Important: python-urwid security update
https://access.redhat.com/errata/RHSA-2026:58562
CVE-2026-9323

+ RHSA-2026:59490 Important: nginx:1.24 security update
https://access.redhat.com/errata/RHSA-2026:59490
CVE-2026-56434
CVE-2026-60005

+ RHSA-2026:59347 Low: httpd security update
https://access.redhat.com/errata/RHSA-2026:59347
CVE-2026-29167

+ RHSA-2026:59152 Important: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:59152
CVE-2026-18295
CVE-2026-18296
CVE-2026-18298
CVE-2026-18299

+ RHSA-2026:59149 Important: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:59149
CVE-2026-43499
CVE-2026-45984
CVE-2026-46116
CVE-2026-46227
CVE-2026-64531

+ RHSA-2026:58982 Moderate: grafana security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:58982
CVE-2026-33376
CVE-2026-33377

+ RHSA-2026:58897 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:58897
CVE-2026-74934
CVE-2026-74935
CVE-2026-74936
CVE-2026-74939
CVE-2026-74940
CVE-2026-74941
CVE-2026-74942
CVE-2026-74943
CVE-2026-74944
CVE-2026-74945
CVE-2026-74946
CVE-2026-74948
CVE-2026-74949
CVE-2026-74953
CVE-2026-74957
CVE-2026-74959
CVE-2026-74960
CVE-2026-74962
CVE-2026-74963
CVE-2026-74964
CVE-2026-74965
CVE-2026-74967
CVE-2026-74969
CVE-2026-74971
CVE-2026-74972
CVE-2026-74973
CVE-2026-74974
CVE-2026-74976
CVE-2026-74983
CVE-2026-74987
CVE-2026-74990

+ Google Chrome 152.0.7977.64/.65 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html

+ Mozilla Firefox 154.0.1 released
https://www.firefox.com/en-US/firefox/154.0.1/releasenotes/

+ Zabbix 7.4.14, 7.0.30 released
https://www.zabbix.com/rn/rn7.4.14
https://www.zabbix.com/rn/rn7.0.30

+ OpenSSL 4.0.2, 3.6.4, 3.5.8, 3.4.7, 3.0.22 released
https://github.com/openssl/openssl/releases#release-openssl-4.0.2
https://github.com/openssl/openssl/releases#release-openssl-3.6.4
https://github.com/openssl/openssl/releases#release-openssl-3.5.8
https://github.com/openssl/openssl/releases#release-openssl-3.4.7
https://github.com/openssl/openssl/releases#release-openssl-3.0.22

+ AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-75803
CVE-2026-75803

+ RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-14457
CVE-2026-14457

+ QUIC Server May Trigger Double Free When Processing INITIAL Packet
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-18798
CVE-2026-18798

+ Excessive Memory Use Buffering DTLS Records for a Future Epoch
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-54874
CVE-2026-54874

+ Heap Buffer Overflow in CMS Key Unwrapping
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63072
CVE-2026-63072

+ Untrusted Sender DN Used as Format String in CMP Response Validation
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63073
CVE-2026-63073

+ CMP Indefinite Cache Growth of ExtraCerts
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63074
CVE-2026-63074

+ QUIC ACK-only Packet Retention Can Cause Memory Exhaustion
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63075
CVE-2026-63075

+ Invalid Pointer Dereference in CMP Server via Crafted protectionAlg
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-63076
CVE-2026-63076

+ JVN#08517956 Apache Struts 2におけるリソース枯渇の脆弱性
https://jvn.jp/jp/JVN08517956/index.html

VU#308749 Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
https://www.kb.cert.org/vuls/id/308749

当事者が語る! トラブルからの脱出
社内システムが使えない ランサム攻撃者がデータ暗号化
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800004/081800104/?ST=nxt_thmit_security

AI時代に必須の備えとは~AIリスク教本 第4回
法を守れば十分とは言い切れず、AIリスク対応が難しい理由
https://xtech.nikkei.com/atcl/nxt/column/18/03713/00004/?ST=nxt_thmit_security

AIパソコン「DGX Spark」試用リポート 第3回
生成AIの学習もこなすDGX Spark、雑誌記事を学ばせて実際に書かせてみた
https://xtech.nikkei.com/atcl/nxt/column/18/03726/081900003/?ST=nxt_thmit_security

ニュース解説
中国AIモデル「Kimi K3」もサンドボックス脱出、評価環境の設定不備を突く
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11984/?ST=nxt_thmit_security

JVNVU#95422936 古野電気製FA-50(簡易型船舶自動識別装置、AIS)におけるハードコードされた認証情報使用および認証欠如の脆弱性
https://jvn.jp/vu/JVNVU95422936/index.html

JVNVU#96980428 KONAMI製METAL GEAR ONLINE 3におけるヒープベースのバッファオーバーフローの脆弱性
https://jvn.jp/vu/JVNVU96980428/index.html

2026年8月25日火曜日

25日 火曜日、先勝

VU#728712 Konami's Metal Gear Online 3 contains a heap-based buffer overflow
https://www.kb.cert.org/vuls/id/728712

AI時代に必須の備えとは~AIリスク教本 第3回
AIリスクが発生する根本要因は? 従来のソフトウエア品質管理が通用せず
https://xtech.nikkei.com/atcl/nxt/column/18/03713/00003/?ST=nxt_thmit_security

AIパソコン「DGX Spark」試用リポート 第2回
DGX Sparkの本命用途は「ローカル推論」、GUIを使った操作も可能に
https://xtech.nikkei.com/atcl/nxt/column/18/03726/081900002/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
小売のREXTでランサムウエア被害、一部休業から全店営業 ポイント停止続く
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900378/?ST=nxt_thmit_security

JVN#33423625 SKYSEA Client ViewおよびSKYMEC IT Managerにおける複数の脆弱性
https://jvn.jp/jp/JVN33423625/index.html

JVN#84326763 SKYSEA Client Viewにおける複数の脆弱性
https://jvn.jp/jp/JVN84326763/index.html

JVN#74538868 サクラエディタにおけるOSコマンドインジェクションの脆弱性
https://jvn.jp/jp/JVN74538868/index.html