Release Info

Advisory: CLSA-2022:1645466687

OS: CentOS 8.4 ELS

Public date: 2022-02-21 00:00:00

Project: glib2

Version: 2.56.4-10.el8.4.1.tuxcare.els1

Errata link: https://errata.cloudlinux.com/centos8.4-els/CLSA-2022-1645466687.html

Changelog

- CVE-2021-28153: g_file_replace() with G_FILE_CREATE_REPLACE_DESTINATION creates empty target for dangling symlink (#1939118) - CVE-2021-3800: Possible privilege escalation thourgh pkexec and aliases (#1938284)

Update

Update command: dnf update glib2*

Packages list

glib2-2.56.4-10.el8.4.1.tuxcare.els1.i686.rpm glib2-devel-2.56.4-10.el8.4.1.tuxcare.els1.x86_64.rpm glib2-fam-2.56.4-10.el8.4.1.tuxcare.els1.x86_64.rpm glib2-devel-2.56.4-10.el8.4.1.tuxcare.els1.i686.rpm glib2-tests-2.56.4-10.el8.4.1.tuxcare.els1.x86_64.rpm glib2-static-2.56.4-10.el8.4.1.tuxcare.els1.x86_64.rpm glib2-2.56.4-10.el8.4.1.tuxcare.els1.x86_64.rpm glib2-doc-2.56.4-10.el8.4.1.tuxcare.els1.noarch.rpm glib2-static-2.56.4-10.el8.4.1.tuxcare.els1.i686.rpm

CVEs

CVE-2021-3800
CVE-2021-28153