Alibaba Security Advisories · November 2020 — Alibaba Security Advisories
18 advisories 28 CVEs 1 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2020-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

HOTFIX-BA-2020:0003

ALINUX 22020-11-24

HOTFIX-BA-2020:0003: kernel-hotfix bugfix update (Important)

Affected products

ProductStatusVendorPackageEcosystem
kernel-hotfix-4121479-21.1.al7 affected Alibaba Cloud kernel-hotfix-4121479-21.1.al7
Upstream advisory

HOTFIX-BA-2020:0004

ALINUX 22020-11-24

HOTFIX-BA-2020:0004: kernel-hotfix bugfix update (Important)

Affected products

ProductStatusVendorPackageEcosystem
kernel-hotfix-4121479-21.2.al7 affected Alibaba Cloud kernel-hotfix-4121479-21.2.al7
Upstream advisory

HOTFIX-BA-2020:0005

ALINUX 22020-11-24

HOTFIX-BA-2020:0005: kernel-hotfix bugfix update (Important)

Affected products

ProductStatusVendorPackageEcosystem
kernel-hotfix-4121479-21.al7 affected Alibaba Cloud kernel-hotfix-4121479-21.al7
Upstream advisory

ALINUX2-SA-2020:0178

ALINUX 22020-11-11

ALINUX2-SA-2020:0178: fence-agents security and bug fix update (Low)

CVEs:CVE-2020-11078

Affected products

ProductStatusVendorPackageEcosystem
fence-agents affected Alibaba Cloud fence-agents
Upstream advisory

ALINUX2-SA-2020:0184

ALINUX 22020-11-11

ALINUX2-SA-2020:0184: qt and qt5-qtbase security update (Moderate)

CVEs:CVE-2020-17507

Affected products

ProductStatusVendorPackageEcosystem
qt affected Alibaba Cloud qt
qt5-qtbase affected Alibaba Cloud qt5-qtbase
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.