2026年9月17日木曜日

17日 木曜日、友引

+ RHSA-2026:68316 Moderate: .NET 8.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68316
CVE-2026-58649

+ RHSA-2026:68233 Important: .NET 9.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68233
CVE-2026-58649
CVE-2026-69806

+ RHSA-2026:67943 Important: python-lxml security update
https://access.redhat.com/errata/RHSA-2026:67943
CVE-2026-49825

+ RHSA-2026:67908 Important: libevent security update
https://access.redhat.com/errata/RHSA-2026:67908
CVE-2026-63382
CVE-2026-63383
CVE-2026-63384
CVE-2026-63385
CVE-2026-63387
CVE-2026-63388

+ RHSA-2026:67832 Important: tesseract security update
https://access.redhat.com/errata/RHSA-2026:67832
CVE-2026-73066

+ Google Chrome 154.0.8037.44/.45 released
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop_096324202.html

+ Mozilla Foundation Security Advisory 2026-96 Security Vulnerabilities fixed in Thunderbird 153.3
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/

+ ISC BIND 9.21.26, 9.20.29 released
https://downloads.isc.org/isc/bind9/9.21.26/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.20.29/doc/arm/html/notes.html

+ BIND 9の脆弱性(High: CVE-2026-19666, CVE-2026-19667, CVE-2026-76163, CVE-2026-77692, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736, Medium: CVE-2026-19033, CVE-2026-19662, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-77119, CVE-2026-78301)と修正バージョン(9.20.29, 9.21.26)
https://security.sios.jp/vulnerability/bind9-security-vulnerability-20260917/
CVE-2026-19666
CVE-2026-19667
CVE-2026-76163
CVE-2026-77692
CVE-2026-80274
CVE-2026-81563
CVE-2026-81736
CVE-2026-19033
CVE-2026-19662
CVE-2026-19668
CVE-2026-19941
CVE-2026-75029
CVE-2026-77119
CVE-2026-78301

VU#369093 MLflow dspy and statsmodels flavors bypass pickle deserialization control
https://www.kb.cert.org/vuls/id/369093

VU#212479 Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
https://www.kb.cert.org/vuls/id/212479

ニュース&リポート
SBOM最小要素、26年版で増加 日本では「推奨」、強制せず
作成負荷増も、運用の自動化にはメリット
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/091001497/?ST=nxt_thmit_security

生成AI時代のOSS危機 第4回
OSSのAI再実装は悪か、波紋呼ぶ「ライセンス洗浄」と貢献の行方
https://xtech.nikkei.com/atcl/nxt/column/18/03754/091100003/?ST=nxt_thmit_security

JVN#95825631 QNDにおける複数の脆弱性
https://jvn.jp/jp/JVN95825631/index.html

JVN#45281119 XikeStor製Layer3スイッチのコンフィグレーションデータダウンロード機能における認証欠如の脆弱性
https://jvn.jp/jp/JVN45281119/index.html

JVNVU#93448623 CISA ICS Advisory / ICS Medical Advisory(2026年09月15日)
https://jvn.jp/vu/JVNVU93448623/index.html

0 件のコメント:

コメントを投稿