-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmj4CNQFAwAAAAAACgkQZ0GeRcM5nt31
iQf/UO/TlDxMNVzE3H4QAbUZUufqU55SXZxREO2kzN8VF4X8t+zKBVlCw6AcWGcGwoTy8b/mFR5l
7QhBNTUqbVnD/oAWLql8V8L2snZAUQUkVRw8rkcpxLCi/3YarHUi4Ulop7M3+GypbyXRCtWDmNiR
nw4B+0l8sleEMQwX07Qk80LIxZxqMyKBkpr8/f3UN+S217YicRAjh7AL6fqPlq9WDf3YzhnEOlM/
1Htw9TLCvXo0mSYCdMWY9t9lsqFvuhYleZ75V9riCDSEOqdKAuWwd4ZX4/tFs+UMcgC+G3vlNKWu
iqMXchjuh/Gq6cFYHjwVhUtXFWu3MWigfebNsbZEOA==
=C+Hl
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7819-2
October 21, 2025
linux-azure-fips vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure-fips: Linux kernel for Microsoft Azure Cloud systems with FIPS
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- Device tree and open firmware driver;
- SCSI subsystem;
- TTY drivers;
- Ext4 file system;
- Network file system (NFS) server daemon;
- SMB network file system;
- Bluetooth subsystem;
- Packet sockets;
- Network traffic control;
- VMware vSockets driver;
(CVE-2025-38350, CVE-2024-57996, CVE-2025-37752, CVE-2025-38617,
CVE-2025-38477, CVE-2025-38083, CVE-2024-38541, CVE-2023-52757,
CVE-2023-52975, CVE-2025-38618, CVE-2024-49950, CVE-2024-50073,
CVE-2025-37785, CVE-2025-21796, CVE-2025-38683, CVE-2025-37797)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.4.0-1155-azure-fips 5.4.0-1155.162+fips1
Available with Ubuntu Pro
linux-image-azure-fips 5.4.0.1155.92
Available with Ubuntu Pro
linux-image-azure-fips-5.4 5.4.0.1155.92
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7819-2
https://ubuntu.com/security/notices/USN-7819-1
CVE-2023-52757, CVE-2023-52975, CVE-2024-38541, CVE-2024-49950,
CVE-2024-50073, CVE-2024-57996, CVE-2025-21796, CVE-2025-37752,
CVE-2025-37785, CVE-2025-37797, CVE-2025-38083, CVE-2025-38350,
CVE-2025-38477, CVE-2025-38617, CVE-2025-38618, CVE-2025-38683
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure-fips/5.4.0-1155.162+fips1
No comments:
Post a Comment