Tuesday, September 1, 2020

[USN-4486-1] Linux kernel vulnerability

==========================================================================
Ubuntu Security Notice USN-4486-1
September 02, 2020

linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi2,
linux-snapdragon vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 14.04 ESM

Summary:

The Linux kernel could be made to crash if it mounted a malicious XFS
file system.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-kvm: Linux kernel for cloud environments
- linux-raspi2: Linux kernel for Raspberry Pi (V8) systems
- linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors
- linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty

Details:

Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly validate meta-data information. An attacker could
use this to construct a malicious xfs image that, when mounted, could cause
a denial of service (system crash).

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
linux-image-4.4.0-1079-kvm 4.4.0-1079.86
linux-image-4.4.0-1113-aws 4.4.0-1113.126
linux-image-4.4.0-1138-raspi2 4.4.0-1138.147
linux-image-4.4.0-1142-snapdragon 4.4.0-1142.151
linux-image-4.4.0-189-generic 4.4.0-189.219
linux-image-4.4.0-189-generic-lpae 4.4.0-189.219
linux-image-4.4.0-189-lowlatency 4.4.0-189.219
linux-image-4.4.0-189-powerpc-e500mc 4.4.0-189.219
linux-image-4.4.0-189-powerpc-smp 4.4.0-189.219
linux-image-4.4.0-189-powerpc64-emb 4.4.0-189.219
linux-image-4.4.0-189-powerpc64-smp 4.4.0-189.219
linux-image-aws 4.4.0.1113.118
linux-image-generic 4.4.0.189.195
linux-image-generic-lpae 4.4.0.189.195
linux-image-kvm 4.4.0.1079.77
linux-image-lowlatency 4.4.0.189.195
linux-image-powerpc-e500mc 4.4.0.189.195
linux-image-powerpc-smp 4.4.0.189.195
linux-image-powerpc64-emb 4.4.0.189.195
linux-image-powerpc64-smp 4.4.0.189.195
linux-image-raspi2 4.4.0.1138.138
linux-image-snapdragon 4.4.0.1142.134
linux-image-virtual 4.4.0.189.195

Ubuntu 14.04 ESM:
linux-image-4.4.0-1077-aws 4.4.0-1077.81
linux-image-4.4.0-189-generic 4.4.0-189.219~14.04.1
linux-image-4.4.0-189-generic-lpae 4.4.0-189.219~14.04.1
linux-image-4.4.0-189-lowlatency 4.4.0-189.219~14.04.1
linux-image-4.4.0-189-powerpc-e500mc 4.4.0-189.219~14.04.1
linux-image-4.4.0-189-powerpc-smp 4.4.0-189.219~14.04.1
linux-image-4.4.0-189-powerpc64-emb 4.4.0-189.219~14.04.1
linux-image-4.4.0-189-powerpc64-smp 4.4.0-189.219~14.04.1
linux-image-aws 4.4.0.1077.74
linux-image-generic-lpae-lts-xenial 4.4.0.189.165
linux-image-generic-lts-xenial 4.4.0.189.165
linux-image-lowlatency-lts-xenial 4.4.0.189.165
linux-image-powerpc-e500mc-lts-xenial 4.4.0.189.165
linux-image-powerpc-smp-lts-xenial 4.4.0.189.165
linux-image-powerpc64-emb-lts-xenial 4.4.0.189.165
linux-image-powerpc64-smp-lts-xenial 4.4.0.189.165
linux-image-virtual-lts-xenial 4.4.0.189.165

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4486-1
CVE-2018-10323

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.4.0-189.219
https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1113.126
https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1079.86
https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1138.147
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1142.151

[USN-4485-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-4485-1
September 02, 2020

linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp,
linux-gcp-4.15, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle,
linux-raspi2, linux-snapdragon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp-4.15: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gke-4.15: Linux kernel for Google Container Engine (GKE) systems
- linux-kvm: Linux kernel for cloud environments
- linux-oem: Linux kernel for OEM systems
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-raspi2: Linux kernel for Raspberry Pi (V8) systems
- linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors
- linux-aws-hwe: Linux kernel for Amazon Web Services (AWS-HWE) systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems

Details:

Timothy Michaud discovered that the i915 graphics driver in the Linux
kernel did not properly validate user memory locations for the
i915_gem_execbuffer2_ioctl. A local attacker could possibly use this to
cause a denial of service or execute arbitrary code. (CVE-2018-20669)

It was discovered that the Kvaser CAN/USB driver in the Linux kernel did
not properly initialize memory in certain situations. A local attacker
could possibly use this to expose sensitive information (kernel memory).
(CVE-2019-19947)

Chuhong Yuan discovered that go7007 USB audio device driver in the Linux
kernel did not properly deallocate memory in some failure conditions. A
physically proximate attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2019-20810)

It was discovered that the elf handling code in the Linux kernel did not
initialize memory before using it in certain situations. A local attacker
could use this to possibly expose sensitive information (kernel memory).
(CVE-2020-10732)

It was discovered that the Linux kernel did not correctly apply Speculative
Store Bypass Disable (SSBD) mitigations in certain situations. A local
attacker could possibly use this to expose sensitive information.
(CVE-2020-10766)

It was discovered that the Linux kernel did not correctly apply Indirect
Branch Predictor Barrier (IBPB) mitigations in certain situations. A local
attacker could possibly use this to expose sensitive information.
(CVE-2020-10767)

It was discovered that the Linux kernel could incorrectly enable Indirect
Branch Speculation after it has been disabled for a process via a prctl()
call. A local attacker could possibly use this to expose sensitive
information. (CVE-2020-10768)

Luca Bruno discovered that the zram module in the Linux kernel did not
properly restrict unprivileged users from accessing the hot_add sysfs file.
A local attacker could use this to cause a denial of service (memory
exhaustion). (CVE-2020-10781)

It was discovered that the XFS file system implementation in the Linux
kernel did not properly validate meta data in some circumstances. An
attacker could use this to construct a malicious XFS image that, when
mounted, could cause a denial of service. (CVE-2020-12655)

It was discovered that the bcache subsystem in the Linux kernel did not
properly release a lock in some error conditions. A local attacker could
possibly use this to cause a denial of service. (CVE-2020-12771)

It was discovered that the Virtual Terminal keyboard driver in the Linux
kernel contained an integer overflow. A local attacker could possibly use
this to have an unspecified impact. (CVE-2020-13974)

Kyungtae Kim discovered that the USB testing driver in the Linux kernel did
not properly deallocate memory on disconnect events. A physically proximate
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2020-15393)

It was discovered that the NFS server implementation in the Linux kernel
did not properly honor umask settings when setting permissions while
creating file system objects if the underlying file system did not support
ACLs. An attacker could possibly use this to expose sensitive information
or violate system integrity. (CVE-2020-24394)

It was discovered that the Kerberos SUNRPC GSS implementation in the Linux
kernel did not properly deallocate memory on module unload. A local
privileged attacker could possibly use this to cause a denial of service
(memory exhaustion). (CVE-2020-12656)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
linux-image-4.15.0-1051-oracle 4.15.0-1051.55
linux-image-4.15.0-1067-gke 4.15.0-1067.70
linux-image-4.15.0-1068-raspi2 4.15.0-1068.72
linux-image-4.15.0-1072-kvm 4.15.0-1072.73
linux-image-4.15.0-1080-aws 4.15.0-1080.84
linux-image-4.15.0-1081-gcp 4.15.0-1081.92
linux-image-4.15.0-1084-snapdragon 4.15.0-1084.92
linux-image-4.15.0-1093-azure 4.15.0-1093.103
linux-image-4.15.0-1094-oem 4.15.0-1094.104
linux-image-4.15.0-115-generic 4.15.0-115.116
linux-image-4.15.0-115-generic-lpae 4.15.0-115.116
linux-image-4.15.0-115-lowlatency 4.15.0-115.116
linux-image-aws-lts-18.04 4.15.0.1080.82
linux-image-azure-lts-18.04 4.15.0.1093.67
linux-image-gcp-lts-18.04 4.15.0.1081.99
linux-image-generic 4.15.0.115.103
linux-image-generic-lpae 4.15.0.115.103
linux-image-gke 4.15.0.1067.71
linux-image-gke-4.15 4.15.0.1067.71
linux-image-kvm 4.15.0.1072.68
linux-image-lowlatency 4.15.0.115.103
linux-image-oem 4.15.0.1094.98
linux-image-oracle-lts-18.04 4.15.0.1051.62
linux-image-powerpc-e500mc 4.15.0.115.103
linux-image-powerpc-smp 4.15.0.115.103
linux-image-powerpc64-emb 4.15.0.115.103
linux-image-powerpc64-smp 4.15.0.115.103
linux-image-raspi2 4.15.0.1068.66
linux-image-snapdragon 4.15.0.1084.87
linux-image-virtual 4.15.0.115.103

Ubuntu 16.04 LTS:
linux-image-4.15.0-1051-oracle 4.15.0-1051.55~16.04.1
linux-image-4.15.0-1080-aws 4.15.0-1080.84~16.04.1
linux-image-4.15.0-1081-gcp 4.15.0-1081.92~16.04.1
linux-image-4.15.0-1093-azure 4.15.0-1093.103~16.04.1
linux-image-aws-hwe 4.15.0.1080.77
linux-image-azure 4.15.0.1093.88
linux-image-azure-edge 4.15.0.1093.88
linux-image-gcp 4.15.0.1081.83
linux-image-gke 4.15.0.1081.83
linux-image-oracle 4.15.0.1051.42

Ubuntu 14.04 ESM:
linux-image-4.15.0-1093-azure 4.15.0-1093.103~14.04.1
linux-image-azure 4.15.0.1093.70

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4485-1
CVE-2018-20669, CVE-2019-19947, CVE-2019-20810, CVE-2020-10732,
CVE-2020-10766, CVE-2020-10767, CVE-2020-10768, CVE-2020-10781,
CVE-2020-12655, CVE-2020-12656, CVE-2020-12771, CVE-2020-13974,
CVE-2020-15393, CVE-2020-24394

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.15.0-115.116
https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1080.84
https://launchpad.net/ubuntu/+source/linux-azure-4.15/4.15.0-1093.103
https://launchpad.net/ubuntu/+source/linux-gcp-4.15/4.15.0-1081.92
https://launchpad.net/ubuntu/+source/linux-gke-4.15/4.15.0-1067.70
https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1072.73
https://launchpad.net/ubuntu/+source/linux-oem/4.15.0-1094.104
https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1051.55
https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1068.72
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1084.92
https://launchpad.net/ubuntu/+source/linux-aws-hwe/4.15.0-1080.84~16.04.1
https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1093.103~16.04.1
https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1081.92~16.04.1
https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1051.55~16.04.1

[USN-4484-1] Linux kernel vulnerability

==========================================================================
Ubuntu Security Notice USN-4484-1
September 02, 2020

linux-hwe, linux-aws-5.3, linux-gke-5.3, linux-raspi2-5.3 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

The system could be made to crash or run programs as an administrator.

Software Description:
- linux-aws-5.3: Linux kernel for Amazon Web Services (AWS) systems
- linux-gke-5.3: Linux kernel for Google Container Engine (GKE) systems
- linux-hwe: Linux hardware enablement (HWE) kernel
- linux-raspi2-5.3: Linux kernel for Raspberry Pi (V8) systems

Details:

It was discovered that the cgroup v2 subsystem in the Linux kernel did not
properly perform reference counting in some situations, leading to a NULL
pointer dereference. A local attacker could use this to cause a denial of
service or possibly gain administrative privileges. (CVE-2020-14356)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
linux-image-5.3.0-1032-raspi2 5.3.0-1032.34
linux-image-5.3.0-1034-aws 5.3.0-1034.36
linux-image-5.3.0-1034-gke 5.3.0-1034.36
linux-image-5.3.0-66-generic 5.3.0-66.60
linux-image-5.3.0-66-lowlatency 5.3.0-66.60
linux-image-aws 5.3.0.1034.33
linux-image-gke-5.3 5.3.0.1034.19
linux-image-gkeop-5.3 5.3.0.66.123
linux-image-raspi2-hwe-18.04 5.3.0.1032.22

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4484-1
CVE-2020-14356

Package Information:
https://launchpad.net/ubuntu/+source/linux-aws-5.3/5.3.0-1034.36
https://launchpad.net/ubuntu/+source/linux-gke-5.3/5.3.0-1034.36
https://launchpad.net/ubuntu/+source/linux-hwe/5.3.0-66.60
https://launchpad.net/ubuntu/+source/linux-raspi2-5.3/5.3.0-1032.34

[USN-4483-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-4483-1
September 02, 2020

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp,
linux-gcp-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi,
linux-raspi-5.4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-kvm: Linux kernel for cloud environments
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-raspi: Linux kernel for Raspberry Pi (V8) systems
- linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems
- linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems
- linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems
- linux-oracle-5.4: Linux kernel for Oracle Cloud systems
- linux-raspi-5.4: Linux kernel for Raspberry Pi (V8) systems

Details:

Chuhong Yuan discovered that go7007 USB audio device driver in the Linux
kernel did not properly deallocate memory in some failure conditions. A
physically proximate attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2019-20810)

Fan Yang discovered that the mremap implementation in the Linux kernel did
not properly handle DAX Huge Pages. A local attacker with access to DAX
storage could use this to gain administrative privileges. (CVE-2020-10757)

It was discovered that the Linux kernel did not correctly apply Speculative
Store Bypass Disable (SSBD) mitigations in certain situations. A local
attacker could possibly use this to expose sensitive information.
(CVE-2020-10766)

It was discovered that the Linux kernel did not correctly apply Indirect
Branch Predictor Barrier (IBPB) mitigations in certain situations. A local
attacker could possibly use this to expose sensitive information.
(CVE-2020-10767)

It was discovered that the Linux kernel could incorrectly enable Indirect
Branch Speculation after it has been disabled for a process via a prctl()
call. A local attacker could possibly use this to expose sensitive
information. (CVE-2020-10768)

Luca Bruno discovered that the zram module in the Linux kernel did not
properly restrict unprivileged users from accessing the hot_add sysfs file.
A local attacker could use this to cause a denial of service (memory
exhaustion). (CVE-2020-10781)

It was discovered that the XFS file system implementation in the Linux
kernel did not properly validate meta data in some circumstances. An
attacker could use this to construct a malicious XFS image that, when
mounted, could cause a denial of service. (CVE-2020-12655)

It was discovered that the bcache subsystem in the Linux kernel did not
properly release a lock in some error conditions. A local attacker could
possibly use this to cause a denial of service. (CVE-2020-12771)

It was discovered that the Virtual Terminal keyboard driver in the Linux
kernel contained an integer overflow. A local attacker could possibly use
this to have an unspecified impact. (CVE-2020-13974)

It was discovered that the cgroup v2 subsystem in the Linux kernel did not
properly perform reference counting in some situations, leading to a NULL
pointer dereference. A local attacker could use this to cause a denial of
service or possibly gain administrative privileges. (CVE-2020-14356)

Kyungtae Kim discovered that the USB testing driver in the Linux kernel did
not properly deallocate memory on disconnect events. A physically proximate
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2020-15393)

It was discovered that the NFS server implementation in the Linux kernel
did not properly honor umask settings when setting permissions while
creating file system objects if the underlying file system did not support
ACLs. An attacker could possibly use this to expose sensitive information
or violate system integrity. (CVE-2020-24394)

It was discovered that the Kerberos SUNRPC GSS implementation in the Linux
kernel did not properly deallocate memory on module unload. A local
privileged attacker could possibly use this to cause a denial of service
(memory exhaustion). (CVE-2020-12656)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
linux-image-5.4.0-1016-raspi 5.4.0-1016.17
linux-image-5.4.0-1022-aws 5.4.0-1022.22
linux-image-5.4.0-1022-gcp 5.4.0-1022.22
linux-image-5.4.0-1022-oracle 5.4.0-1022.22
linux-image-5.4.0-1023-azure 5.4.0-1023.23
linux-image-5.4.0-45-generic 5.4.0-45.49
linux-image-5.4.0-45-generic-lpae 5.4.0-45.49
linux-image-5.4.0-45-lowlatency 5.4.0-45.49
linux-image-aws 5.4.0.1022.23
linux-image-azure 5.4.0.1023.22
linux-image-gcp 5.4.0.1022.20
linux-image-generic 5.4.0.45.49
linux-image-generic-lpae 5.4.0.45.49
linux-image-gke 5.4.0.1022.20
linux-image-kvm 5.4.0.1021.20
linux-image-lowlatency 5.4.0.45.49
linux-image-oem 5.4.0.45.49
linux-image-oem-osp1 5.4.0.45.49
linux-image-oracle 5.4.0.1022.20
linux-image-raspi 5.4.0.1016.51
linux-image-raspi2 5.4.0.1016.51
linux-image-virtual 5.4.0.45.49

Ubuntu 18.04 LTS:
linux-image-5.4.0-1016-raspi 5.4.0-1016.17~18.04.1
linux-image-5.4.0-1022-aws 5.4.0-1022.22~18.04.1
linux-image-5.4.0-1022-gcp 5.4.0-1022.22~18.04.1
linux-image-5.4.0-1022-oracle 5.4.0-1022.22~18.04.1
linux-image-5.4.0-1023-azure 5.4.0-1023.23~18.04.1
linux-image-aws-edge 5.4.0.1022.8
linux-image-azure 5.4.0.1023.7
linux-image-gcp 5.4.0.1022.9
linux-image-gke-5.4 5.4.0.1022.9
linux-image-oracle 5.4.0.1022.7
linux-image-raspi-hwe-18.04 5.4.0.1016.20

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4483-1
CVE-2019-20810, CVE-2020-10757, CVE-2020-10766, CVE-2020-10767,
CVE-2020-10768, CVE-2020-10781, CVE-2020-12655, CVE-2020-12656,
CVE-2020-12771, CVE-2020-13974, CVE-2020-14356, CVE-2020-15393,
CVE-2020-24394

Package Information:
https://launchpad.net/ubuntu/+source/linux/5.4.0-45.49
https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1022.22
https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1023.23
https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1022.22
https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1021.21
https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1022.22
https://launchpad.net/ubuntu/+source/linux-raspi/5.4.0-1016.17
https://launchpad.net/ubuntu/+source/linux-aws-5.4/5.4.0-1022.22~18.04.1
https://launchpad.net/ubuntu/+source/linux-azure-5.4/5.4.0-1023.23~18.04.1
https://launchpad.net/ubuntu/+source/linux-gcp-5.4/5.4.0-1022.22~18.04.1
https://launchpad.net/ubuntu/+source/linux-oracle-5.4/5.4.0-1022.22~18.04.1
https://launchpad.net/ubuntu/+source/linux-raspi-5.4/5.4.0-1016.17~18.04.1

[USN-4482-1] Ark vulnerability

==========================================================================
Ubuntu Security Notice USN-4482-1
September 01, 2020

ark vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Ark could be made to write files as your login if it opened a specially
crafted file.

Software Description:
- ark: archive utility

Details:

Fabian Vogt discovered that Ark incorrectly handled symbolic links in
tar archive files. An attacker could use this to construct a malicious
tar archive that, when opened, would create files outside the extraction
directory.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
ark 4:19.12.3-0ubuntu1.2

Ubuntu 18.04 LTS:
ark 4:17.12.3-0ubuntu1.2

Ubuntu 16.04 LTS:
ark 4:15.12.3-0ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4482-1
CVE-2020-24654

Package Information:
https://launchpad.net/ubuntu/+source/ark/4:19.12.3-0ubuntu1.2
https://launchpad.net/ubuntu/+source/ark/4:17.12.3-0ubuntu1.2
https://launchpad.net/ubuntu/+source/ark/4:15.12.3-0ubuntu1.2

[CentOS-announce] CESA-2020:3558 Important CentOS 6 firefox Security Update

CentOS Errata and Security Advisory 2020:3558 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3558

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
7aaf26cdf6b6fe4bbc989ca9afc2b9a52bbde92a1fc3718cd7ed90d5a5d0875b firefox-68.12.0-1.el6.centos.i686.rpm

x86_64:
7aaf26cdf6b6fe4bbc989ca9afc2b9a52bbde92a1fc3718cd7ed90d5a5d0875b firefox-68.12.0-1.el6.centos.i686.rpm
49b77ef47320110d89f10574d0cc64337dd3e1d704e360de6c09081e8727841b firefox-68.12.0-1.el6.centos.x86_64.rpm

Source:
2be4234b61c9ddbbee04f99bafb4118674334a1dd03cfd8fe2993eadbb594f49 firefox-68.12.0-1.el6.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2020:3556 Important CentOS 7 firefox Security Update

CentOS Errata and Security Advisory 2020:3556 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2020:3556

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
6d8bf16512d109e75893de1fd5c3fff8aa8557a12556eccd6e6c8fbfd7f184ad firefox-68.12.0-1.el7.centos.i686.rpm
843fb795c9bf323f16859c41219123409abcc114812537da012befe15091fbc3 firefox-68.12.0-1.el7.centos.x86_64.rpm

Source:
729023af84d866521eaf2029c1b4cc75e623be9b70f6bfbdf518d431757f4315 firefox-68.12.0-1.el7.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[USN-4481-1] FreeRDP vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl9OWroACgkQZWnYVadE
vpOe3Q/+NaKc5xPlRoXLgBSnESzZYgDFuHQZJMe27dZXhJiACi/P2ZCFp2dopZc5
3dRyYvbMo3oGvdCrWv1lr4/2tLfSxn4BiVWEhmydwOaytsjdg7oTX4z3T8sh+wLR
7zyQJ9WgHDK4pAvV32736Krp9G/bPfRzqXstxTFUy8a6b6wt2ZkM2SvvqLjlIAQd
Q3lLji0beGYbFrPgxNltSwLTcfzFoLgeDZWo3H7XwgcTZffEbu+iUcKvBBqHTm9d
2aj/w06ea6cKxA/NWHpwGVL8YULXGHdXVpfrCD8tyYqLfm86dyGLi7Vp0MEumPa5
YlC1fTV+vzAImut3ofqRMizCCkTj9xaiQExN74cpd8dvkgs4J7TIu+fOnnztehCT
AGktijKvrFOC+M8J/Yk43Cb5savivAB74/U5VFtF4f4tNtlg0VZfYPUYNWh5yUb1
Yaa4KBRJbJGJ67D1Zis2k5SvGZjIJeQf0noX0SaKaowxq/4PB4anrrocrVnvn+fI
1JhkM7aKd/Q6x4f6p+o2hILeSSGC8p39iUXV9Edn7e9yJOfyuuyxtul+/ozg7K8m
Pbs6GjtsUNWXaMjOoglRGgG2gq/HHpHR3eJ2F1q3/Qu/JgJy8nn5/BYx7pN8LIHW
EfsSu8EEnDKg3eeE7P8a+LiAw4ZV87CvGzwx89tMlTum+gpfPnw=
=n4+Z
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-4481-1
September 01, 2020

freerdp2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in FreeRDP.

Software Description:
- freerdp2: RDP client for Windows Terminal Services

Details:

It was discovered that FreeRDP incorrectly handled certain memory
operations. A remote attacker could use this issue to cause FreeRDP to
crash, resulting in a denial of service, or possibly execute arbitrary
code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
libfreerdp-client2-2 2.2.0+dfsg1-0ubuntu0.20.04.1
libfreerdp-server2-2 2.2.0+dfsg1-0ubuntu0.20.04.1
libfreerdp2-2 2.2.0+dfsg1-0ubuntu0.20.04.1

Ubuntu 18.04 LTS:
libfreerdp-client2-2 2.2.0+dfsg1-0ubuntu0.18.04.1
libfreerdp-server2-2 2.2.0+dfsg1-0ubuntu0.18.04.1
libfreerdp2-2 2.2.0+dfsg1-0ubuntu0.18.04.1

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References:
https://usn.ubuntu.com/4481-1
CVE-2020-11095, CVE-2020-11096, CVE-2020-11097, CVE-2020-11098,
CVE-2020-11099, CVE-2020-15103, CVE-2020-4030, CVE-2020-4031,
CVE-2020-4032, CVE-2020-4033

Package Information:
https://launchpad.net/ubuntu/+source/freerdp2/2.2.0+dfsg1-0ubuntu0.20.04.1
https://launchpad.net/ubuntu/+source/freerdp2/2.2.0+dfsg1-0ubuntu0.18.04.1

[USN-4471-2] Net-SNMP regression

==========================================================================
Ubuntu Security Notice USN-4471-2
September 01, 2020

net-snmp regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 ESM

Summary:

USN-4471-1 introduced a regression in Net-SNMP.

Software Description:
- net-snmp: SNMP (Simple Network Management Protocol) server and applications

Details:

USN-4471-1 fixed a vulnerability in Net-SNMP. The updated introduced a regression making
nsExtendCacheTime not settable. This update fixes the problem adding the cacheTime feature flag.

Original advisory details:

Tobias Neitzel discovered that Net-SNMP incorrectly handled certain symlinks.
An attacker could possibly use this issue to access sensitive information.
(CVE-2020-15861)

It was discovered that Net-SNMP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-15862)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
libsnmp-base 5.7.3+dfsg-1.8ubuntu3.6
libsnmp-perl 5.7.3+dfsg-1.8ubuntu3.6
libsnmp30 5.7.3+dfsg-1.8ubuntu3.6
snmpd 5.7.3+dfsg-1.8ubuntu3.6

Ubuntu 16.04 LTS:
libsnmp-base 5.7.3+dfsg-1ubuntu4.6
libsnmp-perl 5.7.3+dfsg-1ubuntu4.6
libsnmp30 5.7.3+dfsg-1ubuntu4.6
snmpd 5.7.3+dfsg-1ubuntu4.6

Ubuntu 14.04 ESM:
libsnmp-base 5.7.2~dfsg-8.1ubuntu3.3+esm2
libsnmp-perl 5.7.2~dfsg-8.1ubuntu3.3+esm2
libsnmp30 5.7.2~dfsg-8.1ubuntu3.3+esm2
snmpd 5.7.2~dfsg-8.1ubuntu3.3+esm2

After a standard system update you need to restart snmpd to make
all the necessary changes.

References:
https://usn.ubuntu.com/4471-2
https://usn.ubuntu.com/4471-1
https://launchpad.net/bugs/1892980

Package Information:
https://launchpad.net/ubuntu/+source/net-snmp/5.7.3+dfsg-1.8ubuntu3.6
https://launchpad.net/ubuntu/+source/net-snmp/5.7.3+dfsg-1ubuntu4.6

[USN-4480-1] OpenStack Keystone vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl9OOXYACgkQZWnYVadE
vpO5ZQ//bQb8hb58+rPV6idIlYnbDJ2nw5Wz3LlvW0fscvPZ/MTe8bj22AJobivx
mTwQXllD1Cv5iX6uZ8KrruI3Y71353E4lAKtVEE+7vb7tftPcNQ/DYJ7w8L9NRxb
gdBB++hZGhglJO/iUBXYYX9mYUG9GeMkxa2sKI/hZcEXTPei1zD8XlUX6W8Wpw7f
DVb2JTRpIgJqFBrdf4RH/HeYBW2jz1suFuySoLklxSbC8Ke1BZboTQ82umKGs5Ny
vwoSLpjJ2bErC57LkRoEMfGJvN2weyxtLusqYcYL0XpPW7+17gHfFLUIYyQq4y2D
nqhFmZZuLZtWka3UaFin3O4k1jQ5SFD0Mx7e5UpZX9G8/AQqtb2RETs0AOvU022Z
t8xCiyb1XQfhROMnX5Jxfa2Sgd/2SrCuAo2GwELsy0jbt62YbPJoJtJGJxEeRLfW
R/VdVCI5G8rVNmboXGLVdC54Y4jIm5N8JuCdisN16sRlxlNDq91dc7CFKzTL9iTX
HrXzr/MT2sXYbh14xxI9EL8xrZo5jsgRTePH1jfB5YE6RsQpb88egvsLUz3CkcNU
YzHzCBBBentj9KEFNgH+7sEAnjzzYQhiU5vMnNkrdyPZDp7QGZzyYbdM9g71Ae04
PIzfZlgm6eJFr4YWHb/9zg6q+MV25jtAFoaVY4mjCaA6JupTLC4=
=NcjT
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-4480-1
September 01, 2020

keystone vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in OpenStack Keystone.

Software Description:
- keystone: OpenStack identity service

Details:

It was discovered that OpenStack Keystone incorrectly handled EC2
credentials. An authenticated attacker with a limited scope could possibly
create EC2 credentials with escalated permissions. (CVE-2020-12689,
CVE-2020-12691)

It was discovered that OpenStack Keystone incorrectly handled the list of
roles provided with OAuth1 access tokens. An authenticated user could
possibly end up with more role assignments than intended. (CVE-2020-12690)

It was discovered that OpenStack Keystone incorrectly handled EC2 signature
TTL checks. A remote attacker could possibly use this issue to reuse
Authorization headers. (CVE-2020-12692)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
keystone 2:13.0.4-0ubuntu1
python-keystone 2:13.0.4-0ubuntu1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4480-1
CVE-2020-12689, CVE-2020-12690, CVE-2020-12691, CVE-2020-12692

Package Information:
https://launchpad.net/ubuntu/+source/keystone/2:13.0.4-0ubuntu1

[USN-4479-1] Django vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl9OOWYACgkQZWnYVadE
vpMBDw//aTcuah1JWbB7TLGKndR57/9IBndQmkQLfwYLIkQ7rFAXJGFnIZzF5Kp+
effLhK1dAg5nxKYpqJ9B/BYh9nbUowQOYVeTrfkSHvAVE9QSF8uTnjII/AFSrHmy
lI6Qg9MByDfxjeFZA8VRcttfUuiq7TmBqM6i62xMXgPHWEs+HPxLrpqtio9D7jYw
kXtv91VYl9s7M/DySYH2HD6lxhRKCZSV6KZgnYWPQ8nb2K+da/pZTxaGZfwz82Ch
YH/TCUP8YT11ybSFR6vWJOe9Lo38ldVAWKDzJ6a1mcWs6280sPiBvpXwHeFmEuKM
qQ5Zi04hq6bmh4+1c+GsJMUN9iOeM2bdordVurqYqM9ayKFiFNVBmbg5TMl69Onb
ymIM+pLPS1+FOIAsl13STfPDs3QVgFFeomrQjXqnpzXKvH6QA6aNX75MIN8bQ2FE
JWedvq85gYCaF++ycNTgE9eev4WVsl/TW1244CbN/Fs1YCg/k1JutKTR06buyOcl
8iZLobIXIQEV/ueM5Y755OcniivGD1TEndTDa0wreeWhLHkmoboKzrVd9MgSNoPq
4Aeo4+gRtLiabUyB0v87eNdNllmXqib870HZQi/grTzeKXEqvzCtjpgG9L8Hx2/F
3zZsDj7lLouJc+RZNqaO981Wbs9jg7/LTNjv5e87qTSeGq3rnNY=
=NJup
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-4479-1
September 01, 2020

python-django vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in Django.

Software Description:
- python-django: High-level Python web development framework

Details:

It was discovered that Django, when used with Python 3.7 or higher,
incorrectly handled directory permissions. A local attacker could possibly
use this issue to obtain sensitive information, or escalate permissions.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
python3-django 2:2.2.12-1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4479-1
CVE-2020-24583, CVE-2020-24584

Package Information:
https://launchpad.net/ubuntu/+source/python-django/2:2.2.12-1ubuntu0.2

lists.linuxfromscratch.org mailing list memberships reminder

This is a reminder, sent out once a month, about your
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.

You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.

In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.

If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!

Passwords for reallost1.fbsd2233449@blogger.com:

List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com