Wednesday, May 9, 2018
[CentOS-announce] CESA-2018:1319 Important CentOS 6 kernel Security Update
Upstream details at : https://access.redhat.com/errata/RHSA-2018:1319
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0ad77fd677aef101b9f6fdd2871173612333281d776520ecfae57c1d381b2e21 kernel-2.6.32-696.28.1.el6.i686.rpm
37e002b4ec8cb0d47e8b9427073dc3209280ffa8307bc28e8e0c7f9d818214ed kernel-abi-whitelists-2.6.32-696.28.1.el6.noarch.rpm
e7e3fd0e9130be40ce38bbdbbe4e971506f3c3db3b24dceb7a6abcdcee47d9de kernel-debug-2.6.32-696.28.1.el6.i686.rpm
77ccfe0bc6ef1e4ee9214036768416b2b528b2aef9e71e3c48d0ca59c004f28f kernel-debug-devel-2.6.32-696.28.1.el6.i686.rpm
cb08256cb0c950a7233e6de90fc2c6464243de381abae903799eb82f5a7edb61 kernel-devel-2.6.32-696.28.1.el6.i686.rpm
9a4a6205260a044053d75a2e167651e69a4e9802ba93f354f261b60879848fb5 kernel-doc-2.6.32-696.28.1.el6.noarch.rpm
cc7e18af2c14a3e6469e551866eb4dceb91e1fffa1f64cb08463494ae514dc8d kernel-firmware-2.6.32-696.28.1.el6.noarch.rpm
82b1ba0334adaf81d1b3bb5a06625dcfa2b7cc2586ab491b104189bcf44a9b95 kernel-headers-2.6.32-696.28.1.el6.i686.rpm
d3d96af0f6309a67bd86ce090b2e48a0396bc0c7a81d58c1f7effe391625b124 perf-2.6.32-696.28.1.el6.i686.rpm
e00c0b060a2ca77eb7f2f0b575d05ef4e9154d5ea03f44d63c22cb69b7fc9903 python-perf-2.6.32-696.28.1.el6.i686.rpm
x86_64:
c1a87ab6d6628639f2456d8f49b4b0fb2f5891eb7a001f00986f9691ebb6e9d1 kernel-2.6.32-696.28.1.el6.x86_64.rpm
37e002b4ec8cb0d47e8b9427073dc3209280ffa8307bc28e8e0c7f9d818214ed kernel-abi-whitelists-2.6.32-696.28.1.el6.noarch.rpm
27211dcac25bc8efdef2b9ad6a7878ad5aff98d2a3195fe087fd4c02cbdd9fdd kernel-debug-2.6.32-696.28.1.el6.x86_64.rpm
77ccfe0bc6ef1e4ee9214036768416b2b528b2aef9e71e3c48d0ca59c004f28f kernel-debug-devel-2.6.32-696.28.1.el6.i686.rpm
ce913ed2cb9ea3799b463808471244f3259973928f8f1dba4d3f868512943f9e kernel-debug-devel-2.6.32-696.28.1.el6.x86_64.rpm
73674be131a5d7a855450f3ec5b3f67956dbb366e854e8909533125fa8b57c6c kernel-devel-2.6.32-696.28.1.el6.x86_64.rpm
9a4a6205260a044053d75a2e167651e69a4e9802ba93f354f261b60879848fb5 kernel-doc-2.6.32-696.28.1.el6.noarch.rpm
cc7e18af2c14a3e6469e551866eb4dceb91e1fffa1f64cb08463494ae514dc8d kernel-firmware-2.6.32-696.28.1.el6.noarch.rpm
95e982222a272bbaf0367c2afe9ca516388e20bf0530d7826cdd9818e7d0b7c0 kernel-headers-2.6.32-696.28.1.el6.x86_64.rpm
c812bdbba530ce27286dc53680d313b5addd290b2cd885413344fcd621dcc18b perf-2.6.32-696.28.1.el6.x86_64.rpm
e763ea6f3f09365ed17624b09330cd918627aa8b6dd6d2d7e896fdb81aa1fe88 python-perf-2.6.32-696.28.1.el6.x86_64.rpm
Source:
fe8e4c2b62e39cb557bb1dd9195bb524b107964a653736103fd59ba6893a3f2c kernel-2.6.32-696.28.1.el6.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEBA-2018:1363 CentOS 6 gcc-libraries BugFix Update
Upstream details at : https://access.redhat.com/errata/RHBA-2018:1363
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
323ad8d5df9a986714d005ef68522add594e30649126df621a17bb4c9b8408f8 libatomic-7.1.1-2.4.1.el6_9.i686.rpm
5a08cc9e5b374e7c7f4bbf8f7a52d3aad149b9e1c0b52f26da74bab204f81819 libcilkrts-7.1.1-2.4.1.el6_9.i686.rpm
e655f830b1cb725f1e16d29ab9523aa05e35652ab0a97f941c98c06f81ae1501 libgfortran4-7.1.1-2.4.1.el6_9.i686.rpm
248c681d393d114567ad1b52f62b3f9bebd4c6f739a940ff58b21a914d958889 libitm-7.1.1-2.4.1.el6_9.i686.rpm
dfcac050acf14a260d070c22b3f259e63810ec6e0c93977d0757fa8619af2a40 libquadmath-7.1.1-2.4.1.el6_9.i686.rpm
x86_64:
323ad8d5df9a986714d005ef68522add594e30649126df621a17bb4c9b8408f8 libatomic-7.1.1-2.4.1.el6_9.i686.rpm
40c821ed28410ef09698e5d30703ee435cbdd59ff93b2331194b58e57d075650 libatomic-7.1.1-2.4.1.el6_9.x86_64.rpm
5a08cc9e5b374e7c7f4bbf8f7a52d3aad149b9e1c0b52f26da74bab204f81819 libcilkrts-7.1.1-2.4.1.el6_9.i686.rpm
36bd5b0cfdc8e04f3386351dd4744246b144f488e8a0eaf480462406738483fc libcilkrts-7.1.1-2.4.1.el6_9.x86_64.rpm
dc79d7bfb19758b5141d1ec39d4a813bd5be49b53b333faa69fe2edde39d6d61 libgfortran4-7.1.1-2.4.1.el6_9.x86_64.rpm
248c681d393d114567ad1b52f62b3f9bebd4c6f739a940ff58b21a914d958889 libitm-7.1.1-2.4.1.el6_9.i686.rpm
cb739fcc5409e8a56b8c4f0408d2888af76aba7a1280ac642c979b41763fbf02 libitm-7.1.1-2.4.1.el6_9.x86_64.rpm
bd53cf22b87e00a8e1303567371c8cd57bcbf7c71df9c093ceb541acfe7a76e9 libquadmath-7.1.1-2.4.1.el6_9.x86_64.rpm
Source:
4281052f332512080e2ff36a0d756738a7e49fc7279dfc5bec82d6ade347d06c gcc-libraries-7.1.1-2.4.1.el6_9.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEBA-2018:1362 CentOS 6 vte BugFix Update
Upstream details at : https://access.redhat.com/errata/RHBA-2018:1362
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
dc5384b49e720518865f72977b64025fd36ed921e27620e18929e33c66749af6 vte-0.25.1-10.el6_9.i686.rpm
0088d97ea239f1818b4deb6a316f6c19029ce7fb47fc09b61201b2304ab787cb vte-devel-0.25.1-10.el6_9.i686.rpm
x86_64:
dc5384b49e720518865f72977b64025fd36ed921e27620e18929e33c66749af6 vte-0.25.1-10.el6_9.i686.rpm
bdd76e5bd5ea79464d420eeb4478c2f1aeaac3aa1eeba1752008a39c20e37a63 vte-0.25.1-10.el6_9.x86_64.rpm
0088d97ea239f1818b4deb6a316f6c19029ce7fb47fc09b61201b2304ab787cb vte-devel-0.25.1-10.el6_9.i686.rpm
74bec8926f4b823d38d0add1f1f15c1a954a963a68dc7ad684c29c135805dc41 vte-devel-0.25.1-10.el6_9.x86_64.rpm
Source:
a13db29c3e6b32fc106022ed39f0dc0e03f04494ba732caa1e89779ac51a4d05 vte-0.25.1-10.el6_9.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEBA-2018:1339 CentOS 6 tzdata BugFix Update
Upstream details at : https://access.redhat.com/errata/RHBA-2018:1339
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
d66cde6ab07be8739b2222c0463cc7c0218a55f1f825944545cef692107ae685 tzdata-2018e-3.el6.noarch.rpm
cb1e4abf1981101afc2a87b1a434068d65e5f2828846bbc051199fda58002bd6 tzdata-java-2018e-3.el6.noarch.rpm
x86_64:
d66cde6ab07be8739b2222c0463cc7c0218a55f1f825944545cef692107ae685 tzdata-2018e-3.el6.noarch.rpm
cb1e4abf1981101afc2a87b1a434068d65e5f2828846bbc051199fda58002bd6 tzdata-java-2018e-3.el6.noarch.rpm
Source:
3e8bd97285bcdc86fd0e2d902ab3ea8cd46bce4ca7ef34f7eee3d2c7ff622d49 tzdata-2018e-3.el6.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEBA-2018:1361 CentOS 6 ibus BugFix Update
Upstream details at : https://access.redhat.com/errata/RHBA-2018:1361
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
7bc067f49bbd933672a1cffff2d19da4d6d4dbf40ccddac3d41630e2176760fb ibus-1.3.4-9.1.el6_9.i686.rpm
42da18ba08e243ad861c1591ab08ea801d79c8c488f09ecdada681b8c86f3134 ibus-devel-1.3.4-9.1.el6_9.i686.rpm
a5a2a6793acf62085b41382192cb9f068310f9b2990cddc337e263ccd71e5fef ibus-devel-docs-1.3.4-9.1.el6_9.i686.rpm
2e9ee4fc8c13fd4cb856bdd0b4aa1213764081db592a251a6b0261ef34f0adc6 ibus-gtk-1.3.4-9.1.el6_9.i686.rpm
15e0440f2e1831a8fcb72b3e4347a03ce91991651e7dfed3510ce9b01b302d2c ibus-libs-1.3.4-9.1.el6_9.i686.rpm
x86_64:
4e33cd4fd1e5b2576012b6a7b9ebaed4bc39bd778fc61b60997edbe04f49dee2 ibus-1.3.4-9.1.el6_9.x86_64.rpm
42da18ba08e243ad861c1591ab08ea801d79c8c488f09ecdada681b8c86f3134 ibus-devel-1.3.4-9.1.el6_9.i686.rpm
164a59cd7aece2e340c04c8d0e15da713419268acb7f8120b0f7b7d56be14061 ibus-devel-1.3.4-9.1.el6_9.x86_64.rpm
c0139fc8389038488e00d15d7dc8fa5453646ea5f8ddeb03da613db48941ecd4 ibus-devel-docs-1.3.4-9.1.el6_9.x86_64.rpm
2e9ee4fc8c13fd4cb856bdd0b4aa1213764081db592a251a6b0261ef34f0adc6 ibus-gtk-1.3.4-9.1.el6_9.i686.rpm
bf9347071d1db29f7d4e32bf12ad5cc2f3a599a7c3fe9a491f1579c948811542 ibus-gtk-1.3.4-9.1.el6_9.x86_64.rpm
15e0440f2e1831a8fcb72b3e4347a03ce91991651e7dfed3510ce9b01b302d2c ibus-libs-1.3.4-9.1.el6_9.i686.rpm
7ee186e307a906c236800d99da26742d9400f5353d8afac64782db5732d7270f ibus-libs-1.3.4-9.1.el6_9.x86_64.rpm
Source:
f8885fae9ced193d7ddd3cd95fe23d3bb37440a1886d483c888b44cc5cf0bb2e ibus-1.3.4-9.1.el6_9.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2018:1364 Important CentOS 6 389-ds-base Security Update
Upstream details at : https://access.redhat.com/errata/RHSA-2018:1364
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
997e67fca6b61e3c9eab8f16cbc39de3420170cc8d075aff9d297de12231037a 389-ds-base-1.2.11.15-95.el6_9.i686.rpm
70a6f320198a67424128fd0f664d6e015f4d691e4834cf2b9c644178adf9694c 389-ds-base-devel-1.2.11.15-95.el6_9.i686.rpm
ea840e718423a3bf6b92192ad026af50ba30a10cf59438386f55f336f650cf4d 389-ds-base-libs-1.2.11.15-95.el6_9.i686.rpm
x86_64:
de4109a1b8a9364f92aa2eab1d2cb6169d89dc9304791f97edc98c8f7499eedb 389-ds-base-1.2.11.15-95.el6_9.x86_64.rpm
70a6f320198a67424128fd0f664d6e015f4d691e4834cf2b9c644178adf9694c 389-ds-base-devel-1.2.11.15-95.el6_9.i686.rpm
6b8c3237c8443e5135a5d94371f4641fe8aa1329ec5c56b91d12832b6d6fb873 389-ds-base-devel-1.2.11.15-95.el6_9.x86_64.rpm
ea840e718423a3bf6b92192ad026af50ba30a10cf59438386f55f336f650cf4d 389-ds-base-libs-1.2.11.15-95.el6_9.i686.rpm
cc5ad7a239fe8dc5b4c03d955f23cfbb7118110d939678256b00fa6906bf2779 389-ds-base-libs-1.2.11.15-95.el6_9.x86_64.rpm
Source:
4c49c3286a5232c30faffb4871fe41cf4f5b47e3632a1f8b8ad71becfba902df 389-ds-base-1.2.11.15-95.el6_9.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
[USN-3643-2] Wget vulnerability
Ubuntu Security Notice USN-3643-2
May 09, 2018
wget vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
Wget could be made to inject arbitrary cookie values.
Software Description:
- wget: retrieves files from the web
Details:
USN-3643-1 fixed a vulnerability in Wget. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this to inject arbitrary cookie values.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 ESM:
wget 1.13.4-2ubuntu1.6
In general, a standard system update will make all the necessary
changes.
References:
https://usn.ubuntu.com/usn/usn-3643-2
https://usn.ubuntu.com/usn/usn-3643-1
CVE-2018-0494
[USN-3643-1] Wget vulnerability
Ubuntu Security Notice USN-3643-1
May 09, 2018
wget vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 17.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Wget could be made to inject arbitrary cookie values.
Software Description:
- wget: retrieves files from the web
Details:
It was discovered that Wget incorrectly handled certain inputs.
An attacker could possibly use this to inject arbitrary cookie values.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
wget 1.19.4-1ubuntu2.1
Ubuntu 17.10:
wget 1.19.1-3ubuntu1.2
Ubuntu 16.04 LTS:
wget 1.17.1-1ubuntu1.4
Ubuntu 14.04 LTS:
wget 1.15-1ubuntu1.14.04.4
In general, a standard system update will make all the necessary
changes.
References:
https://usn.ubuntu.com/usn/usn-3643-1
CVE-2018-0494
Package Information:
https://launchpad.net/ubuntu/+source/wget/1.19.4-1ubuntu2.1
https://launchpad.net/ubuntu/+source/wget/1.19.1-3ubuntu1.2
https://launchpad.net/ubuntu/+source/wget/1.17.1-1ubuntu1.4
https://launchpad.net/ubuntu/+source/wget/1.15-1ubuntu1.14.04.4
[USN-3642-1] DPDK vulnerability
iQIcBAEBCgAGBQJa8vpuAAoJEGVp2FWnRL6Tj1QP/jWjnrJhrDQa6xr0RROoczIC
YWa8nKHhO39XZmNreuxZvRK35+qLcRimLQnfJl0k661yV2fFARYJTZxw/fLey8Uh
CoXa/ZU+yQRtQxNdPijs1HnXl9H00Iq1SbjTzCygBKq3TBxkazUpITySyHt/FRlc
3wARqct2bHX/Ub0TwE1SC/aolAFTcdJ8Glsw3gjrQ3odyX209hsTvAoth0nEMrd+
gQ0GHGKoq7TE/RPQM3CrwU6tlB1sdjTmdwE/R9P4LgsRiRA/wPo5tRrzt7MFf2CC
+JGK5vujy6K088uMnSD79LVc9Q/2ZOG9NMTY7Zq5jwR9R54kQwLsKb0Xv6Zi6fnQ
R2OfuR+7lp5wNgViggf0uOg/BXeglhGyODBssDccpnJ3xkxm5vCefL3klH5lyUHr
wb9pyJzZjfrPKiOGnZTnptfEOSiJ+DaY7SdKeB8RlM8mEqi3lW4k8VXkWS/seIYx
NBmom/qzPk4b8SHXNvjcSIDW/dVUhSxeceFmlEWYnc8y1FHWq5uJoBxdDTvykqqM
l+yMPn30PvAb+4MucxASXThdcSYO4RTFXRQz7VlpFLvHkJRfYFuvWNz9GWqRIjW6
ApPF61ox4/ov8ybM1oLbM0nt4EWQFsTVEMkyKnozvvM0UwlWl2YQ7irDy1WGSKPj
qWQ+XIMd7HgSReUk5MNd
=u4ia
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3642-1
May 09, 2018
dpdk vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
DPDK could be made to expose sensitive information over the network.
Software Description:
- dpdk: set of libraries for fast packet processing
Details:
Maxime Coquelin discovered that DPDK incorrectly handled guest physical
ranges. A malicious guest could use this issue to possibly access sensitive
information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
dpdk 17.11.2-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3642-1
CVE-2018-1059
Package Information:
https://launchpad.net/ubuntu/+source/dpdk/17.11.2-1ubuntu0.1
Tuesday, May 8, 2018
[LSN-0038-1] Linux kernel vulnerability
Kernel Live Patch Security Notice LSN-0038-1
May 8, 2018
linux vulnerability
==========================================================================
A security issue affects these releases of Ubuntu:
| Series | Base kernel | Arch | flavors |
|------------------+--------------+----------+------------------|
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | generic |
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | lowlatency |
| Ubuntu 14.04 LTS | 4.4.0 | amd64 | generic |
| Ubuntu 14.04 LTS | 4.4.0 | amd64 | lowlatency |
Summary:
On May 8, fixes for CVE-2018-1087 and CVE-2018-8897 were released in linux
kernel version 4.4.0-124.148. These CVEs are both related to the way that
the linux kernel handles certain interrupt and exception instructions. If
an interrupt or exception instruction (INT3, SYSCALL, etc.) is immediately
preceded by a MOV SS or POP SS instruction, the resulting interrupt will
be incorrectly handled, possibly crashing the operating system. The issue
can be triggered by an unprivileged user.
The fix for this problem requires modification of the interrupt descriptor
tables (IDT), and modification of the interrupt handlers. Livepatch is
unable to safely modify these areas, so upgrading to a corrected kernel
and rebooting is required to fix the problem.
Additional information about this problem can be found here:
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Pop_SS
Software Description:
- linux: Linux kernel
Update instructions:
The problem can be corrected by installing an updated kernel with these
fixes and rebooting.
References:
CVE-2018-1087, CVE-2018-8897
--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
[USN-3641-2] Linux kernel vulnerabilities
Ubuntu Security Notice USN-3641-2
May 08, 2018
linux, linux-lts-trusty vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise ESM
Details:
USN-3641-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS, Ubuntu 16.04 LTS, and Ubuntu 17.10. This update provides the
corresponding updates for Ubuntu 12.04 ESM.
Nick Peterson discovered that the Linux kernel did not properly handle
debug exceptions following a MOV/POP to SS instruction. A local attacker
could use this to cause a denial of service (system crash). This issue only
affected the amd64 architecture. (CVE-2018-8897)
Andy Lutomirski discovered that the KVM subsystem of the Linux kernel did
not properly emulate the ICEBP instruction following a MOV/POP to SS
instruction. A local attacker in a KVM virtual machine could use this to
cause a denial of service (guest VM crash) or possibly escalate privileges
inside of the virtual machine. This issue only affected the i386 and amd64
architectures. (CVE-2018-1087)
Andy Lutomirski discovered that the Linux kernel did not properly perform
error handling on virtualized debug registers. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2018-1000199)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 ESM:
linux-image-3.13.0-147-generic 3.13.0-147.196~precise1
linux-image-3.13.0-147-generic-lpae 3.13.0-147.196~precise1
linux-image-3.2.0-134-generic 3.2.0-134.180
linux-image-3.2.0-134-generic-pae 3.2.0-134.180
linux-image-3.2.0-134-highbank 3.2.0-134.180
linux-image-3.2.0-134-omap 3.2.0-134.180
linux-image-3.2.0-134-powerpc-smp 3.2.0-134.180
linux-image-3.2.0-134-powerpc64-smp 3.2.0-134.180
linux-image-3.2.0-134-virtual 3.2.0-134.180
linux-image-generic 3.2.0.134.149
linux-image-generic-lpae-lts-trusty 3.13.0.147.138
linux-image-generic-lts-trusty 3.13.0.147.138
linux-image-generic-pae 3.2.0.134.149
linux-image-highbank 3.2.0.134.149
linux-image-omap 3.2.0.134.149
linux-image-powerpc 3.2.0.134.149
linux-image-powerpc-smp 3.2.0.134.149
linux-image-powerpc64-smp 3.2.0.134.149
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://usn.ubuntu.com/usn/usn-3641-2
https://usn.ubuntu.com/usn/usn-3641-1
CVE-2018-1000199, CVE-2018-1087, CVE-2018-8897
[USN-3641-1] Linux kernel vulnerabilities
Ubuntu Security Notice USN-3641-1
May 08, 2018
linux, linux-aws, linux-azure, linux-euclid, linux-gcp, linux-hwe,
linux-kvm, linux-lts-xenial, linux-oem, linux-raspi2, and
linux-snapdragon vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 17.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-raspi2: Linux kernel for Raspberry Pi 2
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-euclid: Linux kernel for Intel Euclid systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe: Linux hardware enablement (HWE) kernel
- linux-kvm: Linux kernel for cloud environments
- linux-oem: Linux kernel for OEM processors
- linux-snapdragon: Linux kernel for Snapdragon processors
- linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty
Details:
Nick Peterson discovered that the Linux kernel did not
properly handle debug exceptions following a MOV/POP to SS
instruction. A local attacker could use this to cause a denial
of service (system crash). This issue only affected the amd64
architecture. (CVE-2018-8897)
Andy Lutomirski discovered that the KVM subsystem of the Linux kernel
did not properly emulate the ICEBP instruction following a MOV/POP
to SS instruction. A local attacker in a KVM virtual machine could
use this to cause a denial of service (guest VM crash) or possibly
escalate privileges inside of the virtual machine. This issue only
affected the i386 and amd64 architectures. (CVE-2018-1087)
Andy Lutomirski discovered that the Linux kernel did not properly
perform error handling on virtualized debug registers. A local
attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2018-1000199)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 17.10:
linux-image-4.13.0-1019-raspi2 4.13.0-1019.20
linux-image-4.13.0-41-generic 4.13.0-41.46
linux-image-4.13.0-41-generic-lpae 4.13.0-41.46
linux-image-4.13.0-41-lowlatency 4.13.0-41.46
linux-image-generic 4.13.0.41.44
linux-image-generic-lpae 4.13.0.41.44
linux-image-lowlatency 4.13.0.41.44
linux-image-raspi2 4.13.0.1019.17
Ubuntu 16.04 LTS:
linux-image-4.13.0-1015-gcp 4.13.0-1015.19
linux-image-4.13.0-1016-azure 4.13.0-1016.19
linux-image-4.13.0-1026-oem 4.13.0-1026.29
linux-image-4.13.0-41-generic 4.13.0-41.46~16.04.1
linux-image-4.13.0-41-generic-lpae 4.13.0-41.46~16.04.1
linux-image-4.13.0-41-lowlatency 4.13.0-41.46~16.04.1
linux-image-4.4.0-1023-kvm 4.4.0-1023.28
linux-image-4.4.0-1057-aws 4.4.0-1057.66
linux-image-4.4.0-1089-raspi2 4.4.0-1089.97
linux-image-4.4.0-1092-snapdragon 4.4.0-1092.97
linux-image-4.4.0-124-generic 4.4.0-124.148
linux-image-4.4.0-124-generic-lpae 4.4.0-124.148
linux-image-4.4.0-124-lowlatency 4.4.0-124.148
linux-image-4.4.0-124-powerpc-e500mc 4.4.0-124.148
linux-image-4.4.0-124-powerpc-smp 4.4.0-124.148
linux-image-4.4.0-124-powerpc64-emb 4.4.0-124.148
linux-image-4.4.0-124-powerpc64-smp 4.4.0-124.148
linux-image-4.4.0-9027-euclid 4.4.0-9027.29
linux-image-aws 4.4.0.1057.59
linux-image-azure 4.13.0.1016.17
linux-image-euclid 4.4.0.9027.28
linux-image-gcp 4.13.0.1015.17
linux-image-generic 4.4.0.124.130
linux-image-generic-hwe-16.04 4.13.0.41.60
linux-image-generic-lpae 4.4.0.124.130
linux-image-generic-lpae-hwe-16.04 4.13.0.41.60
linux-image-gke 4.13.0.1015.17
linux-image-kvm 4.4.0.1023.22
linux-image-lowlatency 4.4.0.124.130
linux-image-lowlatency-hwe-16.04 4.13.0.41.60
linux-image-oem 4.13.0.1026.30
linux-image-powerpc-e500mc 4.4.0.124.130
linux-image-powerpc-smp 4.4.0.124.130
linux-image-powerpc64-emb 4.4.0.124.130
linux-image-powerpc64-smp 4.4.0.124.130
linux-image-raspi2 4.4.0.1089.89
linux-image-snapdragon 4.4.0.1092.84
Ubuntu 14.04 LTS:
linux-image-3.13.0-147-generic 3.13.0-147.196
linux-image-3.13.0-147-generic-lpae 3.13.0-147.196
linux-image-3.13.0-147-lowlatency 3.13.0-147.196
linux-image-3.13.0-147-powerpc-e500 3.13.0-147.196
linux-image-3.13.0-147-powerpc-e500mc 3.13.0-147.196
linux-image-3.13.0-147-powerpc-smp 3.13.0-147.196
linux-image-3.13.0-147-powerpc64-emb 3.13.0-147.196
linux-image-3.13.0-147-powerpc64-smp 3.13.0-147.196
linux-image-4.4.0-1019-aws 4.4.0-1019.19
linux-image-4.4.0-124-generic 4.4.0-124.148~14.04.1
linux-image-4.4.0-124-generic-lpae 4.4.0-124.148~14.04.1
linux-image-4.4.0-124-lowlatency 4.4.0-124.148~14.04.1
linux-image-4.4.0-124-powerpc-e500mc 4.4.0-124.148~14.04.1
linux-image-4.4.0-124-powerpc-smp 4.4.0-124.148~14.04.1
linux-image-4.4.0-124-powerpc64-emb 4.4.0-124.148~14.04.1
linux-image-4.4.0-124-powerpc64-smp 4.4.0-124.148~14.04.1
linux-image-aws 4.4.0.1019.19
linux-image-generic 3.13.0.147.157
linux-image-generic-lpae 3.13.0.147.157
linux-image-generic-lpae-lts-xenial 4.4.0.124.104
linux-image-generic-lts-xenial 4.4.0.124.104
linux-image-generic-pae 3.13.0.147.157
linux-image-lowlatency 3.13.0.147.157
linux-image-lowlatency-lts-xenial 4.4.0.124.104
linux-image-powerpc-e500 3.13.0.147.157
linux-image-powerpc-e500mc 3.13.0.147.157
linux-image-powerpc-e500mc-lts-xenial 4.4.0.124.104
linux-image-powerpc-smp 3.13.0.147.157
linux-image-powerpc-smp-lts-xenial 4.4.0.124.104
linux-image-powerpc64-emb 3.13.0.147.157
linux-image-powerpc64-emb-lts-xenial 4.4.0.124.104
linux-image-powerpc64-smp 3.13.0.147.157
linux-image-powerpc64-smp-lts-xenial 4.4.0.124.104
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://usn.ubuntu.com/usn/usn-3641-1
CVE-2018-1000199, CVE-2018-1087, CVE-2018-8897
Package Information:
https://launchpad.net/ubuntu/+source/linux/4.13.0-41.46
https://launchpad.net/ubuntu/+source/linux-raspi2/4.13.0-1019.20
https://launchpad.net/ubuntu/+source/linux/4.4.0-124.148
https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1057.66
https://launchpad.net/ubuntu/+source/linux-azure/4.13.0-1016.19
https://launchpad.net/ubuntu/+source/linux-euclid/4.4.0-9027.29
https://launchpad.net/ubuntu/+source/linux-gcp/4.13.0-1015.19
https://launchpad.net/ubuntu/+source/linux-hwe/4.13.0-41.46~16.04.1
https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1023.28
https://launchpad.net/ubuntu/+source/linux-oem/4.13.0-1026.29
https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1089.97
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1092.97
https://launchpad.net/ubuntu/+source/linux/3.13.0-147.196
https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1019.19
https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-124.148~14.04.1