Monday, August 1, 2022

OpenBSD Errata: August 2, 2022 (bgpd)

Errata patch for BGP daemon has been released for OpenBSD 7.1.

Binary updates for the amd64, i386 and arm64 platform are available
via the syspatch utility. Source code patches can be found on the
respective errata page:

https://www.openbsd.org/errata71.html

[USN-5543-1] Net-SNMP vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5543-1
August 01, 2022

net-snmp vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in Net-SNMP.

Software Description:
- net-snmp: SNMP (Simple Network Management Protocol) server and applications

Details:

Yu Zhang and Nanyu Zhong discovered that Net-SNMP incorrectly handled
memory operations when processing certain requests. A remote attacker could
use this issue to cause Net-SNMP to crash, resulting in a denial of
service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
libsnmp-perl 5.9.1+dfsg-1ubuntu2.2
libsnmp40 5.9.1+dfsg-1ubuntu2.2
snmp 5.9.1+dfsg-1ubuntu2.2
snmpd 5.9.1+dfsg-1ubuntu2.2

Ubuntu 20.04 LTS:
libsnmp-perl 5.8+dfsg-2ubuntu2.4
libsnmp35 5.8+dfsg-2ubuntu2.4
snmp 5.8+dfsg-2ubuntu2.4
snmpd 5.8+dfsg-2ubuntu2.4

Ubuntu 18.04 LTS:
libsnmp-perl 5.7.3+dfsg-1.8ubuntu3.7
libsnmp30 5.7.3+dfsg-1.8ubuntu3.7
snmp 5.7.3+dfsg-1.8ubuntu3.7
snmpd 5.7.3+dfsg-1.8ubuntu3.7

After a standard system update you need to restart snmpd to make all the
necessary changes.

References:
https://ubuntu.com/security/notices/USN-5543-1
CVE-2022-24805, CVE-2022-24806, CVE-2022-24807, CVE-2022-24808,
CVE-2022-24809, CVE-2022-24810

Package Information:
https://launchpad.net/ubuntu/+source/net-snmp/5.9.1+dfsg-1ubuntu2.2
https://launchpad.net/ubuntu/+source/net-snmp/5.8+dfsg-2ubuntu2.4
https://launchpad.net/ubuntu/+source/net-snmp/5.7.3+dfsg-1.8ubuntu3.7

[USN-5542-1] Samba vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5542-1
August 01, 2022

samba vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in Samba.

Software Description:
- samba: SMB/CIFS file, print, and login server for Unix

Details:

It was discovered that Samba did not handle MaxQueryDuration when being
used in AD DC configurations, contrary to expectations. This issue only
affected Ubuntu 20.04 LTS. (CVE-2021-3670)

Luke Howard discovered that Samba incorrectly handled certain restrictions
associated with changing passwords. A remote attacker being requested to
change passwords could possibly use this issue to escalate privileges.
(CVE-2022-2031)

Luca Moro discovered that Samba incorrectly handled certain SMB1
communications. A remote attacker could possibly use this issue to obtain
sensitive memory contents. (CVE-2022-32742)

Joseph Sutton discovered that Samba incorrectly handled certain password
change requests. A remote attacker could use this issue to change passwords
of other users, resulting in privilege escalation. (CVE-2022-32744)

Joseph Sutton discovered that Samba incorrectly handled certain LDAP add or
modify requests. A remote attacker could possibly use this issue to cause
Samba to crash, resulting in a denial of service. (CVE-2022-32745)

Joseph Sutton and Andrew Bartlett discovered that Samba incorrectly handled
certain LDAP add or modify requests. A remote attacker could possibly use
this issue to cause Samba to crash, resulting in a denial of service.
(CVE-2022-32746)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
samba 2:4.15.9+dfsg-0ubuntu0.2

Ubuntu 20.04 LTS:
samba 2:4.13.17~dfsg-0ubuntu1.20.04.1

The update for Ubuntu 22.04 LTS uses a new upstream release, which includes
additional bug fixes. In general, a standard system update will make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5542-1
CVE-2021-3670, CVE-2022-2031, CVE-2022-32742, CVE-2022-32744,
CVE-2022-32745, CVE-2022-32746

Package Information:
https://launchpad.net/ubuntu/+source/samba/2:4.15.9+dfsg-0ubuntu0.2
https://launchpad.net/ubuntu/+source/samba/2:4.13.17~dfsg-0ubuntu1.20.04.1

List of long term FTBFS packages to be retired in 1 week

Dear maintainers.

Based on the current fail to build from source policy, the following packages
will be retired from Fedora 37 approximately one week before branching (next week).

Policy:
https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails_to_install/

The packages in rawhide were not successfully built at least since Fedora 35.

This report is based on dist tags.

Packages collected via:
https://github.com/hroncok/fedora-report-ftbfs-retirements/blob/master/ftbfs-retirements.ipynb

If you see a package that was built, please let me know.
If you see a package that should be exempted from the process, please let me
know and we can work together to get a FESCo approval for that.

If you see a package that can be rebuilt, please do so.

Package (co)maintainers
==================================================================
golang-grpc-go4 eclipseo, go-sig, jchaloup
lancer willb
php-aws-sdk3 lcts
php-pimple lcts
recorder ddd
rubygem-coffee-rails jaruga, ruby-packagers-sig, vondruch
rubygem-minitest-reporters pvalena
tinygo go-sig, qulogic
uom-parent lberk, mgoodwin, nathans
xs petersen


The following packages require above mentioned packages:
Depending on: golang-grpc-go4 (1)
golang-x-build (maintained by: eclipseo, go-sig, jchaloup)
golang-x-build-0-0.19.20201229git0a4bf69.fc35.src requires
golang(grpc.go4.org) = 0-0.9.20180421git11d0a25.fc34,
golang(grpc.go4.org/codes) = 0-0.9.20180421git11d0a25.fc34
golang-x-build-devel-0-0.19.20201229git0a4bf69.fc35.noarch requires
golang(grpc.go4.org) = 0-0.9.20180421git11d0a25.fc34,
golang(grpc.go4.org/codes) = 0-0.9.20180421git11d0a25.fc34


Affected (co)maintainers (directly and indirectly):
ddd: recorder
eclipseo: golang-grpc-go4
go-sig: golang-grpc-go4, tinygo
jaruga: rubygem-coffee-rails
jchaloup: golang-grpc-go4
lberk: uom-parent
lcts: php-aws-sdk3, php-pimple
mgoodwin: uom-parent
nathans: uom-parent
petersen: xs
pvalena: rubygem-minitest-reporters
qulogic: tinygo
ruby-packagers-sig: rubygem-coffee-rails
vondruch: rubygem-coffee-rails
willb: lancer

--
Miro HronĨok
--
Phone: +420777974800
IRC: mhroncok
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Friday, July 29, 2022

Important changes to software license information in Fedora packages (SPDX and more!)

On behalf of all of the folks working on Fedora licensing improvements,
I have a few things to announce!


New docs site for licensing and other legal topics
--------------------------------------------------

All documentation related to Fedora licensing has moved to a new
section in Fedora Docs, which you can find at:

https://docs.fedoraproject.org/en-US/legal/

Other legal documentation will follow. This follows the overall Fedora
goal of moving active user and contributor documentation away from the
wiki.


Fedora license information in a structured format
-------------------------------------------------

The "good" (allowed) and "bad" (not-allowed) licenses for Fedora are
now stored in a repository, using a simple structured file format for
each license (it's TOML). You can find this at:

https://gitlab.com/fedora/legal/fedora-license-data

This data is then presented in easy tabular format in the
documentation, at:

https://docs.fedoraproject.org/en-US/legal/allowed-licenses/



New policy for the License field in packages — SPDX identifiers!
----------------------------------------------------------------

We're changing the policy for the "License" field in package spec files
to use SPDX license identifiers. Historically, Fedora has represented
licenses using short abbreviations specific to Fedora. In the meantime,
SPDX license identifiers have emerged as a standard, and other
projects, vendors, and developers have started using them. Adopting
SPDX license identifiers provides greater accuracy as to what license
applies, and will make it easier for us to collaborate with other
projects.


Updated licensing policies and processes
----------------------------------------

Fedora licensing policies and processes have been updated to reflect
the above changes. In some cases, this forced deeper thought as to how
these things are decided and why, which led to various discussion on
Fedora mailing lists. In other cases, it prompted better articulation
of guidance that was implicitly understood but not necessarily
explicitly stated.


New guidance on "effective license" analysis
--------------------------------------------

Many software packages consist of code with different free and open
source licenses. Previous practice often involved "simplification" of
the package license field when the packager believed that one license
subsumed the other — for example, using just "GPL" when the source code
includes parts licensed under a BSD-style license as well. Going
forward, packagers and reviewers should not make this kind of analysis,
and rather use (for example) "GPL-2.0-or-later AND MIT". This approach
is easier for packagers to apply in a consistent way.


When do these changes take effect?
----------------------------------

The resulting changes in practice will be applied to new packages and
licenses going forward. It is not necessary to revise existing packages
at this time, although we have provided some guidance for package
maintainers who want to get started. We're in the process of planning a
path for updating existing packages at a larger scale — stay tuned for
more on that!


Thank you everyone!
-------------------

A huge thanks to some key people who have worked tirelessly to make
this happen: David Cantrell, Richard Fontana, Jilayne Lovejoy, Miroslav
Suchý. Behind the scenes support was also provided by David Levine,
Bryan Sutula, and Beatriz Couto. Thank you as well for the valuable
feedback from Fedora community members in various Fedora forums.

Please have a look at the updated information. If you have questions,
please post them to the Fedora Legal mailing list:

https://lists.fedoraproject.org/archives/list/legal@lists.fedoraproject.org/



--
Matthew Miller
<mattdm@fedoraproject.org>
Fedora Project Leader
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Thursday, July 28, 2022

[USN-5541-1] Linux kernel (Azure) vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5541-1
July 28, 2022

linux-azure vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems

Details:

Eric Biederman discovered that the cgroup process migration implementation
in the Linux kernel did not perform permission checks correctly in some
situations. A local attacker could possibly use this to gain administrative
privileges. (CVE-2021-4197)

Jann Horn discovered that the FUSE file system in the Linux kernel
contained a use-after-free vulnerability. A local attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-1011)

Duoming Zhou discovered that the 6pack protocol implementation in the Linux
kernel did not handle detach events properly in some situations, leading to
a use-after-free vulnerability. A local attacker could use this to cause a
denial of service (system crash). (CVE-2022-1198)

Duoming Zhou discovered that the AX.25 amateur radio protocol
implementation in the Linux kernel did not handle detach events properly in
some situations. A local attacker could possibly use this to cause a denial
of service (system crash) or execute arbitrary code. (CVE-2022-1199)

Duoming Zhou discovered race conditions in the AX.25 amateur radio protocol
implementation in the Linux kernel during device detach operations. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2022-1204)

Duoming Zhou discovered race conditions in the AX.25 amateur radio protocol
implementation in the Linux kernel, leading to use-after-free
vulnerabilities. A local attacker could possibly use this to cause a denial
of service (system crash). (CVE-2022-1205)

It was discovered that the PF_KEYv2 implementation in the Linux kernel did
not properly initialize kernel memory in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2022-1353)

It was discovered that the implementation of X.25 network protocols in the
Linux kernel did not terminate link layer sessions properly. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2022-1516)

Zheyu Ma discovered that the Silicon Motion SM712 framebuffer driver in the
Linux kernel did not properly handle very small reads. A local attacker
could use this to cause a denial of service (system crash). (CVE-2022-2380)

It was discovered that the 8 Devices USB2CAN interface implementation in
the Linux kernel did not properly handle certain error conditions, leading
to a double-free. A local attacker could possibly use this to cause a
denial of service (system crash). (CVE-2022-28388)

It was discovered that the Microchip CAN BUS Analyzer interface
implementation in the Linux kernel did not properly handle certain error
conditions, leading to a double-free. A local attacker could possibly use
this to cause a denial of service (system crash). (CVE-2022-28389)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
linux-image-4.15.0-1146-azure 4.15.0-1146.161~16.04.1
linux-image-azure 4.15.0.1146.133

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-5541-1
CVE-2021-4197, CVE-2022-1011, CVE-2022-1198, CVE-2022-1199,
CVE-2022-1204, CVE-2022-1205, CVE-2022-1353, CVE-2022-1516,
CVE-2022-2380, CVE-2022-28388, CVE-2022-28389

[USN-5540-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5540-1
July 28, 2022

linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-kvm: Linux kernel for cloud environments
- linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty

Details:

Liu Jian discovered that the IGMP protocol implementation in the Linux
kernel contained a race condition, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-20141)

It was discovered that the USB gadget subsystem in the Linux kernel did not
properly validate interface descriptor requests. An attacker could possibly
use this to cause a denial of service (system crash). (CVE-2022-25258)

It was discovered that the Remote NDIS (RNDIS) USB gadget implementation in
the Linux kernel did not properly validate the size of the RNDIS_MSG_SET
command. An attacker could possibly use this to expose sensitive
information (kernel memory). (CVE-2022-25375)

Arthur Mongodin discovered that the netfilter subsystem in the Linux kernel
did not properly perform data validation. A local attacker could use this
to escalate privileges in certain situations. (CVE-2022-34918)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
linux-image-4.4.0-1111-kvm 4.4.0-1111.121
linux-image-4.4.0-1146-aws 4.4.0-1146.161
linux-image-4.4.0-230-generic 4.4.0-230.264
linux-image-4.4.0-230-lowlatency 4.4.0-230.264
linux-image-aws 4.4.0.1146.150
linux-image-generic 4.4.0.230.236
linux-image-kvm 4.4.0.1111.108
linux-image-lowlatency 4.4.0.230.236
linux-image-virtual 4.4.0.230.236

Ubuntu 14.04 ESM:
linux-image-4.4.0-1110-aws 4.4.0-1110.116
linux-image-4.4.0-230-generic 4.4.0-230.264~14.04.1
linux-image-4.4.0-230-lowlatency 4.4.0-230.264~14.04.1
linux-image-aws 4.4.0.1110.107
linux-image-generic-lts-xenial 4.4.0.230.200
linux-image-lowlatency-lts-xenial 4.4.0.230.200
linux-image-virtual-lts-xenial 4.4.0.230.200

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-5540-1
CVE-2022-20141, CVE-2022-25258, CVE-2022-25375, CVE-2022-34918

[USN-5539-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5539-1
July 28, 2022

linux-bluefield, linux-gcp-5.4, linux-gke-5.4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-bluefield: Linux kernel for NVIDIA BlueField platforms
- linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gke-5.4: Linux kernel for Google Container Engine (GKE) systems

Details:

It was discovered that the implementation of the 6pack and mkiss protocols
in the Linux kernel did not handle detach events properly in some
situations, leading to a use-after-free vulnerability. A local attacker
could possibly use this to cause a denial of service (system crash).
(CVE-2022-1195)

Duoming Zhou discovered that the AX.25 amateur radio protocol
implementation in the Linux kernel did not handle detach events properly in
some situations. A local attacker could possibly use this to cause a denial
of service (system crash) or execute arbitrary code. (CVE-2022-1199)

Duoming Zhou discovered race conditions in the AX.25 amateur radio protocol
implementation in the Linux kernel during device detach operations. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2022-1204)

Duoming Zhou discovered race conditions in the AX.25 amateur radio protocol
implementation in the Linux kernel, leading to use-after-free
vulnerabilities. A local attacker could possibly use this to cause a denial
of service (system crash). (CVE-2022-1205)

Yongkang Jia discovered that the KVM hypervisor implementation in the Linux
kernel did not properly handle guest TLB mapping invalidation requests in
some situations. An attacker in a guest VM could use this to cause a denial
of service (system crash) in the host OS. (CVE-2022-1789)

It was discovered that the 8 Devices USB2CAN interface implementation in
the Linux kernel did not properly handle certain error conditions, leading
to a double-free. A local attacker could possibly use this to cause a
denial of service (system crash). (CVE-2022-28388)

Minh Yuan discovered that the floppy driver in the Linux kernel contained a
race condition in some situations, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-33981)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
linux-image-5.4.0-1042-bluefield 5.4.0-1042.47
linux-image-bluefield 5.4.0.1042.41

Ubuntu 18.04 LTS:
linux-image-5.4.0-1078-gke 5.4.0-1078.84~18.04.1
linux-image-5.4.0-1084-gcp 5.4.0-1084.92~18.04.1
linux-image-gcp 5.4.0.1084.63
linux-image-gke-5.4 5.4.0.1078.84~18.04.40

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-5539-1
CVE-2022-1195, CVE-2022-1199, CVE-2022-1204, CVE-2022-1205,
CVE-2022-1789, CVE-2022-28388, CVE-2022-33981

Package Information:
https://launchpad.net/ubuntu/+source/linux-bluefield/5.4.0-1042.47
https://launchpad.net/ubuntu/+source/linux-gcp-5.4/5.4.0-1084.92~18.04.1
https://launchpad.net/ubuntu/+source/linux-gke-5.4/5.4.0-1078.84~18.04.1

[USN-5537-2] MySQL vulnerability

==========================================================================
Ubuntu Security Notice USN-5537-2
July 28, 2022

mysql-5.7 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

Several security issues were fixed in MySQL.

Software Description:
- mysql-5.7: MySQL database

Details:

USN-5537-1 fixed a vulnerability in MySQL. This update provides
the corresponding update for Ubuntu 16.04 ESM.

Original advisory details:

Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.

MySQL has been updated to 5.7.39 in Ubuntu 16.04 ESM.

In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.

Please see the following for more information:

https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-39.html
https://www.oracle.com/security-alerts/cpujul2022.html

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
mysql-server-5.7 5.7.39-0ubuntu0.16.04.1+esm2

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References:
https://ubuntu.com/security/notices/USN-5537-2
https://ubuntu.com/security/notices/USN-5537-1
CVE-2022-21515

[USN-5536-1] Firefox vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5536-1
July 28, 2022

firefox vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Firefox could be made to crash or run programs as your login if it
opened a malicious website.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the mouse
pointer position, bypass Subresource Integrity protections, obtain
sensitive information, or execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
firefox 103.0+build1-0ubuntu0.20.04.1

Ubuntu 18.04 LTS:
firefox 103.0+build1-0ubuntu0.18.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5536-1
CVE-2022-2505, CVE-2022-36315, CVE-2022-36316, CVE-2022-36318,
CVE-2022-36319, CVE-2022-36320

Package Information:
https://launchpad.net/ubuntu/+source/firefox/103.0+build1-0ubuntu0.20.04.1
https://launchpad.net/ubuntu/+source/firefox/103.0+build1-0ubuntu0.18.04.1

[USN-5538-1] libtirpc vulnerability

==========================================================================
Ubuntu Security Notice USN-5538-1
July 28, 2022

libtirpc vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

libtirpc could be made to denial of service if it received a specially
crafted input.

Software Description:
- libtirpc: transport-independent RPC library - common files

Details:

It was discovered that libtirpc incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
libtirpc3 1.3.2-2ubuntu0.1

Ubuntu 20.04 LTS:
libtirpc3 1.2.5-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5538-1
CVE-2021-46828

Package Information:
https://launchpad.net/ubuntu/+source/libtirpc/1.3.2-2ubuntu0.1
https://launchpad.net/ubuntu/+source/libtirpc/1.2.5-1ubuntu0.1

[USN-5537-1] MySQL vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5537-1
July 28, 2022

mysql-5.7, mysql-8.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in MySQL.

Software Description:
- mysql-8.0: MySQL database
- mysql-5.7: MySQL database

Details:

Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.

MySQL has been updated to 8.0.30 in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
Ubuntu 18.04 LTS has been updated to MySQL 5.7.39.

In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.

Please see the following for more information:

https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-39.html
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-30.html
https://www.oracle.com/security-alerts/cpujul2022.html

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
mysql-server-8.0 8.0.30-0ubuntu0.22.04.1

Ubuntu 20.04 LTS:
mysql-server-8.0 8.0.30-0ubuntu0.20.04.2

Ubuntu 18.04 LTS:
mysql-server-5.7 5.7.39-0ubuntu0.18.04.2

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References:
https://ubuntu.com/security/notices/USN-5537-1
CVE-2022-21509, CVE-2022-21515, CVE-2022-21517, CVE-2022-21522,
CVE-2022-21525, CVE-2022-21526, CVE-2022-21527, CVE-2022-21528,
CVE-2022-21529, CVE-2022-21530, CVE-2022-21531, CVE-2022-21534,
CVE-2022-21537, CVE-2022-21538, CVE-2022-21539, CVE-2022-21547,
CVE-2022-21553, CVE-2022-21569

Package Information:
https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.30-0ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.30-0ubuntu0.20.04.2
https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.39-0ubuntu0.18.04.2