SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

厂商发布

厂商对产品安全、配置或策略的更新说明。

  • ALINUX3-SA-2026:0151

    发布时间 2026-06-11 17:37 (UTC+08:00) 抓取时间 2026-06-11 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2026-49975: Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. **Solution**: 请您尽快将升级到修复后的版本。修复

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0151",
      "affected_products": [
        "Alinux 3.2104",
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2026-49975"
      ],
      "raw_pub_date": "Thu, 11 Jun 2026 17:37:20 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0151"
    }
    阿里云 Linux 安全公告 cve:cve-2026-49975 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0150

    发布时间 2026-06-11 17:37 (UTC+08:00) 抓取时间 2026-06-11 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2026-49975: Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. CVE-2026-9256: NGINX Plus and NG

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0150",
      "affected_products": [
        "Alinux 3.2104",
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2026-49975",
        "CVE-2026-9256"
      ],
      "raw_pub_date": "Thu, 11 Jun 2026 17:37:07 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0150"
    }
    阿里云 Linux 安全公告 cve:cve-2026-49975 cve:cve-2026-9256 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0149

    发布时间 2026-06-11 17:36 (UTC+08:00) 抓取时间 2026-06-11 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2026-33811: When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash. CVE-2026-33814: When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0149",
      "affected_products": [
        "Alinux 3.2104",
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2026-27142",
        "CVE-2026-33811",
        "CVE-2026-33814",
        "CVE-2026-39817",
        "CVE-2026-39819",
        "CVE-2026-39820",
        "CVE-2026-39823",
        "CVE-2026-39825",
        "CVE-2026-39826",
        "CVE-2026-39836",
        "CVE-2026-42499",
        "CVE-2026-42501"
      ],
      "raw_pub_date": "Thu, 11 Jun 2026 17:36:17 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0149"
    }
    阿里云 Linux 安全公告 cve:cve-2026-27142 cve:cve-2026-33811 cve:cve-2026-33814 cve:cve-2026-39817 cve:cve-2026-39819 cve:cve-2026-39820 cve:cve-2026-39823 cve:cve-2026-39825 cve:cve-2026-39826 cve:cve-2026-39836 cve:cve-2026-42499 cve:cve-2026-42501 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0148

    发布时间 2026-06-11 17:35 (UTC+08:00) 抓取时间 2026-06-11 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2025-53020: Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue. CVE-2026-28780: Heap-

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0148",
      "affected_products": [
        "Alinux 3.2104",
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2025-53020",
        "CVE-2026-28780",
        "CVE-2026-33007",
        "CVE-2026-33857",
        "CVE-2026-34032",
        "CVE-2026-34059"
      ],
      "raw_pub_date": "Thu, 11 Jun 2026 17:35:43 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0148"
    }
    阿里云 Linux 安全公告 cve:cve-2025-53020 cve:cve-2026-28780 cve:cve-2026-33007 cve:cve-2026-33857 cve:cve-2026-34032 cve:cve-2026-34059 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0147

    发布时间 2026-06-11 17:35 (UTC+08:00) 抓取时间 2026-06-11 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2026-35177: Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-5390

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0147",
      "affected_products": [
        "Alinux 3.2104",
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2025-53906",
        "CVE-2026-35177"
      ],
      "raw_pub_date": "Thu, 11 Jun 2026 17:35:31 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0147"
    }
    阿里云 Linux 安全公告 cve:cve-2025-53906 cve:cve-2026-35177 severity:moderate type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0146

    发布时间 2026-06-11 17:35 (UTC+08:00) 抓取时间 2026-06-12 00:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. **Solution**: 请您尽快将升级到修复后的版本。修复命令如下: yum update --advisory ALINUX3-SA-2026:0146 **Affe

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0146",
      "affected_products": [
        "Alinux 3.2104",
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2026-45186"
      ],
      "raw_pub_date": "Thu, 11 Jun 2026 17:35:19 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0146"
    }
    阿里云 Linux 安全公告 cve:cve-2026-45186 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0145

    发布时间 2026-06-11 17:34 (UTC+08:00) 抓取时间 2026-06-11 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2026-33845: A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause inf

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0145",
      "affected_products": [
        "Alinux 3.2104",
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2026-33845",
        "CVE-2026-33846",
        "CVE-2026-3833",
        "CVE-2026-42009",
        "CVE-2026-42010",
        "CVE-2026-42011",
        "CVE-2026-42012",
        "CVE-2026-42013",
        "CVE-2026-42014",
        "CVE-2026-42015",
        "CVE-2026-5260"
      ],
      "raw_pub_date": "Thu, 11 Jun 2026 17:34:48 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0145"
    }
    阿里云 Linux 安全公告 cve:cve-2026-33845 cve:cve-2026-33846 cve:cve-2026-3833 cve:cve-2026-42009 cve:cve-2026-42010 cve:cve-2026-42011 cve:cve-2026-42012 cve:cve-2026-42013 cve:cve-2026-42014 cve:cve-2026-42015 cve:cve-2026-5260 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update
  • ALINUX3-SA-2026:0144

    发布时间 2026-06-11 17:34 (UTC+08:00) 抓取时间 2026-06-11 18:00 (UTC+08:00)

    Package updates are available for Alibaba Cloud Linux 3 that fix the following vulnerabilities: CVE-2026-4775: A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write

    扩展字段
    {
      "advisory_id": "ALINUX3-SA-2026:0144",
      "affected_products": [
        "Alinux 3.2104",
        "Alinux 3 Pro"
      ],
      "cve_ids": [
        "CVE-2026-4775"
      ],
      "raw_pub_date": "Thu, 11 Jun 2026 17:34:18 +0800",
      "solution": "请您尽快将升级到修复后的版本。修复命令如下:\nyum update --advisory ALINUX3-SA-2026:0144"
    }
    阿里云 Linux 安全公告 cve:cve-2026-4775 severity:important type:advisory vendor:alibaba cve official_advisory vendor-update