This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 1mo
Forensics & Incident Response
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
intrusion-detection
monitoring
security
sql
Summary
AI summaryFixes heap buffer overflows, use-after-free, permission errors, and certificate column issues.
Full changelog
This is a bug and security fix release.
What's Changed
Fixes
- Fix heap buffer overflow in Windows
processestable by @seph in https://github.com/osquery/osquery/pull/8934 - Fix heap buffer overflow in Windows
authenticodetable by @seph in https://github.com/osquery/osquery/pull/8923 - Fix use-after-free in Linux
process_file_events implementationby @zwass in https://github.com/osquery/osquery/pull/8950 - Fix incorrect permissions on temporary file carve directories by @zwass in https://github.com/osquery/osquery/pull/8961
- Fix documentation for
process_open_handlestable by @seph in https://github.com/osquery/osquery/pull/8853 - Fix
subject2andissuer2columns for Windowscertificatestable by @getvictor in https://github.com/osquery/osquery/pull/8963
Full Changelog: https://github.com/osquery/osquery/compare/5.23.0...5.23.1
Security Fixes
- Fix heap buffer overflow in Windows `processes` table
- Fix heap buffer overflow in Windows `authenticode` table
- Fix use-after-free in Linux `process_file_events` implementation
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About osquery
SQL powered operating system instrumentation, monitoring, and analytics
Related context
Beta — feedback welcome: [email protected]