Tuesday, December 5, 2023

FreeBSD Errata Notice FreeBSD-EN-23:15.sanitizer [REVISED]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-EN-23:15.sanitizer Errata Notice
The FreeBSD Project

Topic: Clang sanitizer failure with ASLR enabled

Category: contrib
Module: compiler-rt
Announced: 2023-12-01
Affects: FreeBSD 13.2 and FreeBSD 14.0
Corrected: 2023-11-25 09:05:09 UTC (stable/14, 14.0-STABLE)
2023-12-01 00:38:35 UTC (releng/14.0, 14.0-RELEASE-p1)
2023-11-25 09:05:14 UTC (stable/13, 13.2-STABLE)
2023-12-05 18:20:00 UTC (releng/13.2, 13.2-RELEASE-p7)

For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.

0. Revision History

v1.0 2023-12-01 -- Initial release
v1.1 2023-12-05 -- Updated affected versions and added patch FreeBSD 13.2

I. Background

Compiler-RT is an implementation of various compiler runtime support routines,
provided by the LLVM project. This library also provides a number of so-called
Sanitizers, which help to catch buffer overruns, thread data races, and so on:
AddressSanitizer, ThreadSanitizer, UndefinedBehaviorSanitizer, and more.

II. Problem Description

Some of the Sanitizers cannot work correctly when ASLR is enabled. Therefore, at
the initialization of such Sanitizers, ASLR is detected via procctl(2). If ASLR
is enabled, it is first disabled, and then the main executable containing the
Sanitizer is re-executed, after printing an appropriate message.

However, the Sanitizers work by intercepting various function calls, and by
mistake the already-intercepted procctl(2) function was used. This causes an
internal error, which usually results in a segfault.

III. Impact

Binaries linked to AddressSanitizer (using -fsanitize=address), MemorySanitizer
(using -fsanitize=memory) or ThreadSanitizer (using -fsanitize=thread) can crash
at startup with a segfault, if ASLR is enabled. Other binaries are not affected.

IV. Workaround

If ASLR is enabled system-wide, the problem can be worked around by running the
specific binary with proccontrol(1), to temporarily disable ASLR for only that
program. For example:

proccontrol -m aslr -s disable /path/to/example_program

V. Solution

Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.

No reboot is necessary, but Sanitized binaries must be re-linked, because the
Sanitizer libraries are statically linked in.

Perform one of the following:

1) To update your system via a binary patch:

Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms,
or the i386 platform on FreeBSD 13 and earlier, can be updated via
the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

No reboot is necessary, but Sanitized binaries must be re-linked, because the
Sanitizer libraries are statically linked in.

2) To update your system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

[FreeBSD 14.0]
# fetch https://security.FreeBSD.org/patches/EN-23:15/sanitizer.patch
# fetch https://security.FreeBSD.org/patches/EN-23:15/sanitizer.patch.asc
# gpg --verify sanitizer.patch.asc

[FreeBSD 13.2]
# fetch https://security.FreeBSD.org/patches/EN-23:15/sanitizer.13.patch
# fetch https://security.FreeBSD.org/patches/EN-23:15/sanitizer.13.patch.asc
# gpg --verify sanitizer.13.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile the operating system using buildworld and installworld as
described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>.

VI. Correction details

This issue is corrected as of the corresponding Git commit hash or Subversion
revision number in the following stable and release branches:

Branch/path Hash Revision
- -------------------------------------------------------------------------
stable/14/ 1e4798e9677f stable/14-n265803
releng/14.0/ 78b4c762b20b releng/14.0-n265381
stable/13/ 7c25a53a2cb9 stable/13-n256726
releng/13.2/ 6d94fc2b0db9 releng/13.2-n254646
- -------------------------------------------------------------------------

Run the following command to see which files were modified by a
particular commit:

# git show --stat <commit hash>

Or visit the following URL, replacing NNNNNN with the hash:

<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>

To determine the commit count in a working tree (for comparison against
nNNNNNN in the table above), run:

# git rev-list --count --first-parent HEAD

VII. References

<URL:https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=275270>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-23:15.sanitizer.asc>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEthUnfoEIffdcgYM7bljekB8AGu8FAmVvdI0ACgkQbljekB8A
Gu/tzA//WlbAichQYjs2EOKsBkikGpWRf/Vg3PNpwfT0Bh8Nkuapf8H41Cm0prRT
ZNgwqOcckJK+pj/e99nz3/nxdIJLkzyGMUblAhpkvklXK4KXGT9ASgkzXShyKlIC
nXY7OfEwxUJ/N74Ty6+2d/ZkAIVV+f7A3r4OJ6sPVkB5TDbddg4NbzhMNi+yg3lg
tujrBdmXxSTlBEKy2WVwMyWTrK9lfkDmp0GfbaGvODYhzdNZpfvQ5WEw4rCiC7x9
4zE5YbbtOgZ1zG2tJz/Mklv+dQQFmCf6W3E2aCzhtyw0qcvy5LlYO8oTeDA6LVD5
neWRVXjRk7/g/fLe1dBAbn7loRxglWtnvSdYZU3iZRxgX3Mn+s5zrKhNXmF6QIVM
ppuSI6N9dXaeI4dlFTF+oZkNuP9UFS5thhFmRONES55gifWYGm3YphetrcEIRGBW
WgLUdxE33mALlFOhHSSCmkrqWe59iLjRnbC14HaB4K/fzePZsRd9onqRarEeVQz5
BzDN6t+w0kuBKjjMpmZS3wg0waK7E2YuVdk9nazGS3Mg3YXEdB0Z7lK8AnNLKRJr
Ih/4h1Cj/vyie0j9n0zezgcTdCR/1sNU7+19NCGWhXr3Bwl9OhDuRsz1056Bt1N+
CvdwFB7e7CzoMcOrQC/X2z0qSmX7TvQ6Fx777vK+Cr167NE9mM4=
=Lf9R
-----END PGP SIGNATURE-----

F40 Change Proposal: Unified Kernel Support Phase Two (System-Wide)

This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.

== Summary ==
Improve support for unified kernels in Fedora.

== Owner ==
* Name: [[User:kraxel| Gerd Hoffmann]]
* Email: kraxel@redhat.com

* Name: [[User:vittyvk| Vitaly Kuznetsov]]
* Email: vkuznets@redhat.com


== Detailed Description ==
See [[ Changes/Unified_Kernel_Support_Phase_1 ]] for overview and Phase 1 goals.

==== Phase 2 goals ====

* Add support for booting UKIs directly.
** Boot path is shim.efi -> UKI, without any boot loader (grub,
sd-boot) involved.
** The UEFI boot configuration will get an entry for each kernel installed.
** Newly installed kernels are configured to be booted once (via BootNext).
** Successful boot of the system will make the kernel update permanent
(update BootOrder).
* Enable UKIs for aarch64.
** Should be just flipping the switch, dependencies such as kernel
zboot support are merged.
* Add a UEFI-only cloud image variant which uses UKIs.
** Also suitable for being used in confidential VMs.
** Cover both x86_64 and aarch64.

==== Related bugs ====

* shim: remove dependency on grub2-efi-x64
([https://bugzilla.redhat.com/show_bug.cgi?id=2240989 buzilla
2240989])
* shim: handling of multiple lines in BOOT.CSV is inconsistent
([https://issues.redhat.com/browse/RHEL-10704 jira RHEL-10704],
[https://github.com/rhboot/shim/issues/554 github 554])
* anaconda: add support for
[https://www.freedesktop.org/wiki/Specifications/DiscoverablePartitionsSpec/
discoverable partitions]
([https://bugzilla.redhat.com/show_bug.cgi?id=2160074 bugzilla
2160074], [https://bugzilla.redhat.com/show_bug.cgi?id=2178043
bugzilla 2178043])
* dracut: do not create yet another initramfs for UKIs
([https://github.com/dracutdevs/dracut/pull/2521 github PR 2521])
* kernel: enable UKIs on aarch64
([https://gitlab.com/cki-project/kernel-ark/-/merge_requests/2818 MR
2818])

== Feedback ==


== Benefit to Fedora ==
* Better secure boot support: the UKI initrd is covered by the signature.
* Better support for tpm measurements and confidential computing.
** measurements are more useful if we know what hashes to expect for the initrd.
** measurements are more useful without grub.efi in the boot path
(which measures each grub.cfg line processed).
* More robust boot process
** generating the initrd on the installed system is fragile

== Scope ==
* Proposal owners:
** updates for virt-firmware and uki-direct packages.
** enable UKIs on aarch64
([https://gitlab.com/cki-project/kernel-ark/-/merge_requests/2818 MR
2818]).
** prepare kickstart ([https://pagure.io/fedora-kickstarts.git Fedora
kickstarts]) changes for generating UKI enabled images.

* Other developers:
** installer/anaconda: implement discoverable partition support.
** bootloader/shim: fix bugs.
** Fedora Cloud SIG: Add UKI enabled images as an option to
[https://fedoraproject.org/cloud/download Download Fedora Cloud]
** See also: [https://fedoraproject.org/wiki/Changes/Unified_Kernel_Support_Phase_2#Related_bugs
Related Bugs] section.

* Release engineering: [https://pagure.io/releng/issues #Releng issue number]

* Policies and guidelines: N/A (not needed for this Change)

* Trademark approval: N/A (not needed for this Change)


* Alignment with Objectives:


== Upgrade/compatibility impact ==

None, it's opt-in. Also the uefi cloud image is an additional image
and will not replace the current bios/uefi hybrid image.


== How To Test ==


==== Switch an existing install to use UKIs. ====

Needs up-to-date Fedora 39 or Rawhide install in a virtual machine.
Bare metal hardware with standard storage (ahci / nvme) should work too.

Needs an big enough ESP to store UKI images there (minimum 200M,
recommended 500M).

1. dnf install virt-firmware uki-direct
* The uki-direct package contains the kernel-install plugin and
systemd unit needed to automatically manage kernel updates.
* You should have version 23.10 or newer.

2. sh /usr/share/doc/python3-virt-firmware/experimental/fixup-partitions-for-uki.sh
* Workaround for [https://bugzilla.redhat.com/show_bug.cgi?id=2160074
bug 2160074] (anaconda not setting up
[https://www.freedesktop.org/wiki/Specifications/DiscoverablePartitionsSpec/
discoverable partitions]).
* UKIs need this to find the root filesystem without root=... on the
kernel command line.

3. dnf install kernel-uki-virt

4. kernel-bootcfg --show
* optional step, shows UEFI boot configuration, the new UKI should be
added as BootNext

$ kernel-bootcfg --show
# C - BootCurrent, N - BootNext, O - BootOrder
# --------------------------------------------
# N - 0008 - 6.5.7-300.fc39.x86_64 <= entry for
the the new kernel
# C O - 0007 - 6.5.6-300.fc39.x86_64 <= currently
running kernel
# O - 0006 - Fedora <= grub2 entry
# O - 0001 - UEFI QEMU QEMU HARDDISK
[ ... ]

5. reboot

6. kernel-bootcfg --show
* optional again, after successful boot the new kernel should be first
in BootOrder.

$ kernel-bootcfg --show
# C - BootCurrent, N - BootNext, O - BootOrder
# --------------------------------------------
# C O - 0008 - 6.5.7-300.fc39.x86_64
# O - 0007 - 6.5.6-300.fc39.x86_64
# O - 0006 - Fedora
# O - 0001 - UEFI QEMU QEMU HARDDISK
[ ... ]

==== Test UKI cloud images ====
Repo with kickstart files and scripts: https://gitlab.com/kraxel/fedora-uki

Images for download: https://www.kraxel.org/fedora-uki/
* fedora-uki-cloud: uki-based cloud image, use cloud-init to configure this.
* fedora-uki-direct: minimal uki-based image, root password is 'root'.
* fedora-classic: minimal non-uki image, root password is 'root'.

Known problems:
* images can fail to boot on the first attempt
** should that happen reset the guest once, the second and all
following boots will work fine.
** root cause is a shim bug
([https://github.com/rhboot/shim/issues/554 github 554]).
** known workaround: add a vTPM to the guest configuration.

==== Booting another kernel ====

From the booted system:

* uefi-boot-menu --reboot

From the firmware:

If your UEFI firmware offers an boot menu you should be able to use
that to select the kernel to boot. Unfortunately this is not
standardized so there is no standard procedure to do so.

* Virtual machines (OVMF): Enter the firmware setup by pressing ESC
when you see the tianocore splash screen. Select "Boot Manager" in
the toplevel menu.
* Thinkpad laptops: Interupt normal boot (just 'Enter' on recent
hardware, or using the special key on older models), then press F12
("choose a temporary startup device").

== User Experience ==


== Dependencies ==


== Contingency Plan ==

* Contingency mechanism:
** drop kickstart file for the uefi-only cloud image.
* Contingency deadline: N/A (not a System Wide Change)
* Blocks release? No


== Documentation ==

N/A (not a System Wide Change)

== Release Notes ==



--
Aoife Moloney

Fedora Operations Architect

Fedora Project

Matrix: @amoloney:fedora.im

IRC: amoloney
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

Fedora Linux 37 is EOL

Hello all,

Fedora Linux 37 has gone end of life for updates and support on 2023-12-05.
No more updates of any kind, including security updates or security
announcements, will be available for Fedora Linux 37 after the said
date. All the updates of Fedora Linux 37 being pushed to stable will be
stopped as well.

Fedora Linux 38 will continue to receive updates until approximately
one month after the release of Fedora Linux 40. The maintenance
schedule of Fedora Linux releases is documented on the Fedora Project
wiki [1]. The Fedora Project wiki also contains instructions[2] on how
to upgrade from a previous release of Fedora Linux to a version
receiving updates.

This email template is also in https://pagure.io/releng if you wish to
propose improvements or changes to it.
 

Regards,
Tomas Hrcka
Fedora Release Engineering

[1] - https://fedoraproject.org/wiki/Fedora_Release_Life_Cycle#Maintenance_Schedule
[2] - https://fedoraproject.org/wiki/Upgrading?rd=DistributionUpgrades
[3] - https://pagure.io/releng

--
Tomas Hrcka
fas: humaton
libera.CHAT: jednorozec

[USN-6531-1] Redis vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEhC9y9XdAFQPCvYXchGmXSGiknnUFAmVvV1oFAwAAAAAACgkQhGmXSGiknnV6
xA//Y4SRcu4z/0SXRBG0+6tcoTgwoSsPsYiE214KtZgLZJttoxz8mGG6Rjyg3XUcUDFqNAdN+nwc
B152l7ycPWNkAV9j5WPFTSC8Wq4aBUYjinvzdGiBoN5Xg0dii9rGBiNgNNbznptz/veWDGvXrhYl
vzHiK2R0jDjFeBiWyLF5RJ20x02vVgu2E0weWnyKy7Qs+faHbMBeRferYsI22XHWzEThfFCZbaOq
KCeBNG67hUE//15NQauDCedp7gta7Ds1wkkOwqxQ3TpBj6I76fCuIuolRQ9qWHBOcJZbxAvYji3P
bT+WQvKbfZoTvKqQDsemVFbwZlh2Vutycn5ncMJ+7PbNpO7Nt8I4/y0T5cAXOxQwCdLS/JgZ7kTG
ku6c55jcZdMt23t63ptuPz3FxrEtlBkCeasN/drFavJ5snzG1t0xAWws3WF16GbIsIGV03TqxbwD
vB+5NKGUkk0OHDbaARo75oqnrZxcuTWw8ufLW3XUG9p+bkWqFLMQZgIqWguzCNOoX+1H5eXwtelS
p13KQMHlY2iG/B04UKc4FJHOwkIY5FUFWXbh+YVMVw6EWb0vOsZC4bec2+Xz8vO6a0DdecpDS2im
UmnP5psSFmirBKK+xjfZwTki2XZ69eM7kGrd7c7yPBH53RhTSvdHSHLQO/ezt2dCKzZVZCQEcRlU
hLU=
=2BEk
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6531-1
December 05, 2023

redis vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS (Available with Ubuntu Pro)
- Ubuntu 20.04 LTS (Available with Ubuntu Pro)
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)

Summary:

Several security issues were fixed in Redis.

Software Description:
- redis: Persistent key-value database with network interface

Details:

Seiya Nakata and Yudai Fujiwara discovered that Redis incorrectly handled
certain specially crafted Lua scripts. An attacker could possibly use this
issue to cause heap corruption and execute arbitrary code.
(CVE-2022-24834)

SeungHyun Lee discovered that Redis incorrectly handled specially crafted
commands. An attacker could possibly use this issue to trigger an integer
overflow, which might cause Redis to allocate impossible amounts of memory,
resulting in a denial of service via an application crash. (CVE-2022-35977)

Tom Levy discovered that Redis incorrectly handled crafted string matching
patterns. An attacker could possibly use this issue to cause Redis to hang,
resulting in a denial of service. (CVE-2022-36021)

Yupeng Yang discovered that Redis incorrectly handled specially crafted
commands. An attacker could possibly use this issue to trigger an integer
overflow, resulting in a denial of service via an application crash.
(CVE-2023-25155)

It was discovered that Redis incorrectly handled a specially crafted
command. An attacker could possibly use this issue to create an invalid
hash field, which could potentially cause Redis to crash on future access.
(CVE-2023-28856)

Alexander Aleksandrovič Klimov discovered that Redis incorrectly listened
to a Unix socket before setting proper permissions. A local attacker could
possibly use this issue to connect, bypassing intended permissions.
(CVE-2023-45145)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS (Available with Ubuntu Pro):
redis-server 5:6.0.16-1ubuntu1+esm1
redis-tools 5:6.0.16-1ubuntu1+esm1

Ubuntu 20.04 LTS (Available with Ubuntu Pro):
redis-server 5:5.0.7-2ubuntu0.1+esm2
redis-tools 5:5.0.7-2ubuntu0.1+esm2

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
redis-server 5:4.0.9-1ubuntu0.2+esm4
redis-tools 5:4.0.9-1ubuntu0.2+esm4

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
redis-server 2:3.0.6-1ubuntu0.4+esm2
redis-tools 2:3.0.6-1ubuntu0.4+esm2

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
redis-server 2:2.8.4-2ubuntu0.2+esm3
redis-tools 2:2.8.4-2ubuntu0.2+esm3

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6531-1
CVE-2022-24834, CVE-2022-35977, CVE-2022-36021, CVE-2023-25155,
CVE-2023-28856, CVE-2023-45145

[USN-6530-1] HAProxy vulnerability

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmVvN3MACgkQZWnYVadE
vpOnPA/+K1jIyjSntBdiek8pDL1Mrhfnu1nJjtUasAXW5Ch9Us0n09gSoXqQ9H7A
IBIyE3si7kd4iqjHljqMBtgBUogmXXEAGWTBXhOQDm7FEzhmnntGWkUxtBnpk5UC
+15BhGRLN29VRWOPyhzvR3k/ugPdYLQduMiAMDkj2NXh9Z4G24hGgiYAShcHgkVg
XoAAGFPxLv9w8iVpmEVx/+rj7+qa5wFZusPSXrNetVAe35SKzUystj9kjvtCYiAh
ayewDbnhKhP6T4OH1aSSFqwXl32MfWHUEDPfq5v4cbzb+TmtWUjLnzgv+wb4WAyO
+wS0OLYYbSvFvP94jQdVyYNJyVegHhjwgqqTtu7rK9pG1CY83w3KvuOVXHE4/sBc
sfF9aTITkmofPwse9vbk/DY7uHVW05HmPiSjoPGgcHW+YSbiOE2Y0LWgOKjnWb6Q
4Z6u7B/8idyisCGGPGBK8UbqkAheauqp8ypP4F+/Sfk2taIn4Y8htjIdYnmpX2qT
Yh7A9Q74rUL67qpJEK5vnYem1BpyktfgoXw1I+I+Mku4J6xsrmWPg0iL3ffzCO57
oVbOPyyviA6/yf9oFoEHrlnv7mR0xfUGmTPbwWgsx9fg8WufVtKe8/1+Mh+Pf4Y6
lu6Rhto0+g0+9F4PqVEC7f8unby8MwdLCUOQI4vPhFY2HoR8inY=
=mztn
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6530-1
December 05, 2023

haproxy vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

HAProxy could be made to expose sensitive information.

Software Description:
- haproxy: fast and reliable load balancing reverse proxy

Details:

It was discovered that HAProxy incorrectly handled URI components
containing the hash character (#). A remote attacker could possibly use
this issue to obtain sensitive information, or to bypass certain path_end
rules.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.04:
haproxy 2.6.9-1ubuntu1.2

Ubuntu 22.04 LTS:
haproxy 2.4.22-0ubuntu0.22.04.3

Ubuntu 20.04 LTS:
haproxy 2.0.31-0ubuntu0.3

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6530-1
CVE-2023-45539

Package Information:
https://launchpad.net/ubuntu/+source/haproxy/2.6.9-1ubuntu1.2
https://launchpad.net/ubuntu/+source/haproxy/2.4.22-0ubuntu0.22.04.3
https://launchpad.net/ubuntu/+source/haproxy/2.0.31-0ubuntu0.3

Monday, December 4, 2023

[USN-6529-1] Request Tracker vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmVuMg8FAwAAAAAACgkQVjg+NdFTuLIR
Mgv/bducRThTWL7oVfSNh1Ynga5DqIn781DeTTK9rPYUpt749AKuWudm8F+CMdceMMnl6TlQ+aAm
hSHN26XVCqHHEohVzeyQrOYtqTuNYD7Tcm3BhEIAJMEZdLMhYtG2xDsUM68kIDuPu/TBSpTLizXV
I+IAw8BUA3P2ImvXTGyANj9mnxD/Sxf4gNQWuXzdymZsQAXMF2Sz3nS2lvZQ0Orx7+KjiNB8qxbM
UTS49Mvlw/sHqXc3o4HLGcMNW7tpqXT0G6BFeACLt/pGZKwRpt/GmF+u65s79ZF+A6ooug4Ndhoq
YDZ/T6OLz8oCuEyby62cDs9JVfJUS+HaPnNqettAr7jv3i94ZmZoy5Tooi+ooTvH1baoV3waehTv
rv0tTlGT1Am40ii+oy5olep9RWPDWhJrF0qITPXGKY4yHbQ0pg3ijQQWhLTvScpGlFHvOLuQKWNP
zKpxYVMo232wmsB8MOkkr/sUSQoKKEuRmr/SlATCe+0aLjrZaMmfKLmZfZ8D
=2SGQ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6529-1
December 04, 2023

request-tracker4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.10
- Ubuntu 23.04
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)

Summary:

Several security issues were fixed in Request Tracker.

Software Description:
- request-tracker4: An enterprise-grade issue tracking system

Details:

It was discovered that Request Tracker incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information. (CVE-2021-38562, CVE-2022-25802, CVE-2023-41259,
CVE-2023-41260)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
request-tracker4 4.4.4+dfsg-2ubuntu1.23.10.1
rt4-apache2 4.4.4+dfsg-2ubuntu1.23.10.1
rt4-clients 4.4.4+dfsg-2ubuntu1.23.10.1
rt4-db-mysql 4.4.4+dfsg-2ubuntu1.23.10.1
rt4-db-postgresql 4.4.4+dfsg-2ubuntu1.23.10.1
rt4-db-sqlite 4.4.4+dfsg-2ubuntu1.23.10.1
rt4-fcgi 4.4.4+dfsg-2ubuntu1.23.10.1
rt4-standalone 4.4.4+dfsg-2ubuntu1.23.10.1

Ubuntu 23.04:
request-tracker4 4.4.4+dfsg-2ubuntu1.23.04.1
rt4-apache2 4.4.4+dfsg-2ubuntu1.23.04.1
rt4-clients 4.4.4+dfsg-2ubuntu1.23.04.1
rt4-db-mysql 4.4.4+dfsg-2ubuntu1.23.04.1
rt4-db-postgresql 4.4.4+dfsg-2ubuntu1.23.04.1
rt4-db-sqlite 4.4.4+dfsg-2ubuntu1.23.04.1
rt4-fcgi 4.4.4+dfsg-2ubuntu1.23.04.1
rt4-standalone 4.4.4+dfsg-2ubuntu1.23.04.1

Ubuntu 22.04 LTS:
request-tracker4 4.4.4+dfsg-2ubuntu1.22.04.1
rt4-apache2 4.4.4+dfsg-2ubuntu1.22.04.1
rt4-clients 4.4.4+dfsg-2ubuntu1.22.04.1
rt4-db-mysql 4.4.4+dfsg-2ubuntu1.22.04.1
rt4-db-postgresql 4.4.4+dfsg-2ubuntu1.22.04.1
rt4-db-sqlite 4.4.4+dfsg-2ubuntu1.22.04.1
rt4-fcgi 4.4.4+dfsg-2ubuntu1.22.04.1
rt4-standalone 4.4.4+dfsg-2ubuntu1.22.04.1

Ubuntu 20.04 LTS:
request-tracker4 4.4.3-2+deb10u3build0.20.04.1
rt4-apache2 4.4.3-2+deb10u3build0.20.04.1
rt4-clients 4.4.3-2+deb10u3build0.20.04.1
rt4-db-mysql 4.4.3-2+deb10u3build0.20.04.1
rt4-db-postgresql 4.4.3-2+deb10u3build0.20.04.1
rt4-db-sqlite 4.4.3-2+deb10u3build0.20.04.1
rt4-fcgi 4.4.3-2+deb10u3build0.20.04.1
rt4-standalone 4.4.3-2+deb10u3build0.20.04.1

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
request-tracker4 4.4.2-2ubuntu0.1~esm1
rt4-apache2 4.4.2-2ubuntu0.1~esm1
rt4-clients 4.4.2-2ubuntu0.1~esm1
rt4-db-mysql 4.4.2-2ubuntu0.1~esm1
rt4-db-postgresql 4.4.2-2ubuntu0.1~esm1
rt4-db-sqlite 4.4.2-2ubuntu0.1~esm1
rt4-fcgi 4.4.2-2ubuntu0.1~esm1
rt4-standalone 4.4.2-2ubuntu0.1~esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6529-1
CVE-2021-38562, CVE-2022-25802, CVE-2023-41259, CVE-2023-41260

Package Information:
https://launchpad.net/ubuntu/+source/request-tracker4/4.4.4+dfsg-2ubuntu1.23.10.1
https://launchpad.net/ubuntu/+source/request-tracker4/4.4.4+dfsg-2ubuntu1.23.04.1
https://launchpad.net/ubuntu/+source/request-tracker4/4.4.4+dfsg-2ubuntu1.22.04.1

https://launchpad.net/ubuntu/+source/request-tracker4/4.4.3-2+deb10u3build0.20.04.1

Sunday, December 3, 2023

[announce] BSDCan 2024 website live, CFP soon to follow

BSDCan 2024:

Tutorials: 29-30 May 2024 (Wed/Thu)
Conference: 31 May - 01 June 2024 (Fri/Sat)
CFP opens shortly.

Come and see the Redundant Array of Independent Dans in person!

bsdcan.org/2024/
_______________________________________________
announce mailing list
announce@lists.nycbug.org
https://lists.nycbug.org:8443/mailman/listinfo/announce

[USN-6509-2] Firefox regressions

-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEAPYWTpwtIbr7xH4OWNrRIKaTkWcFAmVtT8YFAwAAAAAACgkQWNrRIKaTkWdE
CRAAhCx/LyM17JwibY+AscSE1qISx7pFfy87dkVR6BLda/B08mjeJLwkp+F/viD6DKNkJlTEmyvR
KVRK/QEXv7vwmXXBpSRYlvfDrXGoHkkd0WbvK7ieU2ztRUKfzpb0Juz7YtDro95RY22gfBiMd/uU
qd+E6jDJcxuMZEc7t5npf7Fcb2xI0M+w3gdfDVFt66uB7cwoKEydMchT4jqRBydzEnj+huEO+bIN
5vNcfemqLXGaZrlcOk22UjQhiwpR8CrDbj8extJGCNst7KnRBoSTs3JataahS908Yix4KDNPewEz
4knPTd4nEpgP/zJIz1p4eYEXafh4xNFPt+KLo3ZanA3ITCjgKGWlRnLxQPpq8RGQlMgxNE5KzX4v
SfI3XCtPXgppmGx96IJooyjKeXY5qdo59HDaQZhwO4yscf3BNln6a2kFPTl+dLkAXvMCzzJMavQ0
FMZ1ZDORhLfxU767ww2WICwMY5DJGZQgwys2swEIKyIaY47MbNZvmKFmfSxKK7RSNVOuJRYIlLYH
+ULfaQkrS9RhH1DFhXangd+RzdtFJIilGTIMJXDV/04f9IdlpnzkvQuA99AJJ9/pRnig8ugt72LH
O36+kTnVzkWh4OGvjy1dQbTR3CmrIfzfa5oDP32DHM/AcsujIRfE9LF1YcKUF8G7KqVwjCtoZer0
no4=
=xbwi
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6509-2
December 04, 2023

firefox regressions
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

USN-6509-1 caused some minor regressions in Firefox.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

USN-6509-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-6206,
CVE-2023-6210, CVE-2023-6211, CVE-2023-6212, CVE-2023-6213)

It was discovered that Firefox did not properly manage memory when
images were created on the canvas element. An attacker could potentially
exploit this issue to obtain sensitive information. (CVE-2023-6204)

It discovered that Firefox incorrectly handled certain memory when using a
MessagePort. An attacker could potentially exploit this issue to cause a
denial of service. (CVE-2023-6205)

It discovered that Firefox incorrectly did not properly manage ownership
in ReadableByteStreams. An attacker could potentially exploit this issue
to cause a denial of service. (CVE-2023-6207)

It discovered that Firefox incorrectly did not properly manage copy
operations when using Selection API in X11. An attacker could potentially
exploit this issue to obtain sensitive information. (CVE-2023-6208)

Rachmat Abdul Rokhim discovered incorrectly handled parsing of relative
URLS starting with "///". An attacker could potentially exploit this issue
to cause a denial of service. (CVE-2023-6209)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
firefox 120.0.1+build1-0ubuntu0.20.04.1

After a standard system update you need to restart Firefox to make all the
necessary changes.

References:
https://ubuntu.com/security/notices/USN-6509-2
https://ubuntu.com/security/notices/USN-6509-1
https://launchpad.net/bugs/2045518

Package Information:
https://launchpad.net/ubuntu/+source/firefox/120.0.1+build1-0ubuntu0.20.04.1

[arch-announce] Bugtracker migration to GitLab completed

We are happy to announce that the [migration of the bugtracker to GitLab][0] is done! 🥳

Thanks to everyone who has helped during the migration!

This means the issue tracker and merge requests on the GitLab package repos are now enabled.

The old bugtracker will subsequently be closed down. For archiving reasons there will be a static copy so that links (for example the randomly picked [Task #56716][1]) are still stable, migrated bugs have a closing comment pointing to the new URL on GitLab.

Packaging bugs are now opened on the repo hosting the corresponding packaging sources, the &quot;Add a new Bug&quot; button on the package page on archlinux.org will automatically direct you to the correct place to open the issue. The workflow afterwards is mostly the same, first our [Bug Wranglers][2] will have a look at the issues and triage them, and then they will be handed over to the respective [Package Maintainers][3] to fix. A list of all issues can be found [here][4].

If you do not have an account for GitLab already (which authenticates against our [SSO service][5]), please write us a mail with your desired username to accountsupport@archlinux.org as advised in the banner.

[0]: https://lists.archlinux.org/hyperkitty/list/arch-dev-public@lists.archlinux.org/thread/WYXDTJ3TR2DWRQCDZK44BQDH67IDVGTS/
[1]: https://bugs.archlinux.org/task/56716
[2]: https://gitlab.archlinux.org/groups/archlinux/teams/bug-wranglers/-/group_members
[3]: https://gitlab.archlinux.org/archlinux/teams/package-maintainer-team
[4]: https://gitlab.archlinux.org/groups/archlinux/packaging/-/issues
[5]: https://accounts.archlinux.org/

URL: https://archlinux.org/news/bugtracker-migration-to-gitlab-completed/

Thursday, November 30, 2023

FreeBSD Errata Notice FreeBSD-EN-23:16.openzfs

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-EN-23:16.openzfs Errata Notice
The FreeBSD Project

Topic: OpenZFS data corruption

Category: contrib
Module: OpenZFS
Announced: 2023-12-01
Affects: All supported versions of FreeBSD.
Corrected: 2023-11-28 21:00:48 UTC (stable/14, 14.0-STABLE)
2023-12-01 00:38:38 UTC (releng/14.0, 14.0-RELEASE-p1)
2023-11-28 21:07:30 UTC (stable/13, 13.2-STABLE)
2023-12-01 00:38:47 UTC (releng/13.2, 13.2-RELEASE-p6)
2023-11-30 05:28:33 UTC (stable/12, 12.4-STABLE)
2023-12-01 00:40:23 UTC (releng/12.4, 12.4-RELEASE-p8)

For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.

I. Background

FreeBSD has included a version of the powerful and feature-rich ZFS file
system beginning with FreeBSD 7.0 released in 2008. The ZFS implementation
in FreeBSD 12 and earlier is based on the Illumos ZFS codebase. In FreeBSD
13 and later OpenZFS is used as the ZFS implementation.

Sparse files in a file system refer to a technique that optimizes storage
space by allowing the creation of files with unallocated or unwritten gaps,
known as holes. When reading a file, holes appear as zero or NUL bytes.
Certain system calls can access hole location metadata, including lseek(2)
with SEEK_HOLE and copy_file_range(2).

In OpenZFS a dnode is a data structure used to represent and manage metadata
about files and directories. In file systems, "dirty" refers to data or
metadata that has been modified in memory but not yet written to the storage
device. Thus, a dirty dnode is one which has uncommitted data or metadata.

In FreeBSD 13.2 and FreeBSD 14.0 cp(1) uses copy_file_range(2) to perform the
data copying in the kernel. copy_file_range attempts to find file holes in
the source file and preserve them in the copy. In FreeBSD 12.4 cp does not
use copy_file_range.

II. Problem Description

A check did not test both the dnode itself and its data for dirtiness. This
provides a very small window of time while a file is being modified where the
dirtiness check can falsely report that the dnode is clean. If this happens
a hole may incorrectly be reported where data was written.

III. Impact

If an access occurs while a file is being modified and a hole is incorrectly
reported, the data may instead be interpreted as zero bytes. Any application
which checks for holes may be affected by this issue; if this occurs during a
file copy it will result in a corrupt copy that retains the incorrect data.
Note that the source file remains intact (a subsequent read will return the
correct data).

IV. Workaround

Setting the vfs.zfs.dmu_offset_next_sync sysctl to 0 disables forcing
TXG sync to find holes. This is an effective workaround that greatly
reduces the likelihood of encountering data corruption, although it does
not completely eliminate it. Note that with the workaround holes will
not be reported in recently dirtied files. See the zfs(4) man page for
more information of the impact of this sysctl setting.

The workaround should be removed once the system is updated to include the
fix described in this notice.

V. Solution

Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date, and reboot.

Perform one of the following:

1) To update your system via a binary patch:

Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms,
or the i386 platfrom on FreeBSD 13 and earlier, can be updated via
the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install
# shutdown -r +10min "Rebooting to apply OpenZFS erratum update"

2) To update your system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

NOTE: The FreeBSD 14.0 patch includes additional bug fixes which were found
during the investigation of this issue. These bug fixes do not apply to
FreeBSD 13.2 or FreeBSD 12.4.

[FreeBSD 14.0]
# fetch https://security.FreeBSD.org/patches/EN-23:16/openzfs.14.patch
# fetch https://security.FreeBSD.org/patches/EN-23:16/openzfs.14.patch.asc
# gpg --verify openzfs.14.patch.asc

[FreeBSD 13.2]
# fetch https://security.FreeBSD.org/patches/EN-23:16/openzfs.13.patch
# fetch https://security.FreeBSD.org/patches/EN-23:16/openzfs.13.patch.asc
# gpg --verify openzfs.13.patch.asc

[FreeBSD 12.4]
# fetch https://security.FreeBSD.org/patches/EN-23:16/openzfs.12.patch
# fetch https://security.FreeBSD.org/patches/EN-23:16/openzfs.12.patch.asc
# gpg --verify openzfs.12.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile your kernel as described in
<URL:https://docs.freebsd.org/en/books/handbook/kernelconfig/> and reboot the
system.

VI. Correction details

This issue is corrected as of the corresponding Git commit hash or Subversion
revision number in the following stable and release branches:

Branch/path Hash Revision
- -------------------------------------------------------------------------
stable/14/ 99385ec7c296 stable/14-n265836
releng/14.0/ 154870526943 releng/14.0-n265384
stable/13/ 5858f93a8b66 stable/13-n256744
releng/13.2/ 0bb76997ce58 releng/13.2-n254644
stable/12/ r373278
releng/12.4/ r373279
- -------------------------------------------------------------------------

For FreeBSD 13 and later:

Run the following command to see which files were modified by a
particular commit:

# git show --stat <commit hash>

Or visit the following URL, replacing NNNNNN with the hash:

<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>

To determine the commit count in a working tree (for comparison against
nNNNNNN in the table above), run:

# git rev-list --count --first-parent HEAD

For FreeBSD 12 and earlier:

Run the following command to see which files were modified by a particular
revision, replacing NNNNNN with the revision number:

# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base

Or visit the following URL, replacing NNNNNN with the revision number:

<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>

VII. References

<URL:https://bugs.freebsd.org/275308>
<URL:https://github.com/openzfs/zfs/issues/11900>
<URL:https://github.com/openzfs/zfs/issues/15526>
<URL:https://github.com/openzfs/zfs/pull/15566>
<URL:https://github.com/openzfs/zfs/pull/15571>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-23:16.openzfs.asc>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEthUnfoEIffdcgYM7bljekB8AGu8FAmVpPo4ACgkQbljekB8A
Gu/7rg/8DV0CgrVWVW8lvywaBry/oFOAcB1s+b49fcW1wt4g4GOnFtU0VGuRYXJh
2pT2xnCVKgWKWciaFAoFN/N29GOxCuMkcPNoYPf8laiBNAmYTGGBMK6FI4YukI2V
6GKSU8hYPgxwRSRW7ZSXfzWl2MuLI2NdrRZwY+L/2cgr/uJVq/u7b1s7y7A9CdbQ
0euotytR77yrSHecA7Ye5PVRFp1behuiK9kbIVUTdFJRB0eQkpap5e3Af9b7GeLe
t3kFI5cHKim7PnquLpljxjRxwcWKeJBMf0a8X6nhXYJ7FHxh6YfRL1t4tPQIRHLq
5A4x9oDoZP5kPRQgdxYT4J/VuoCEsq9/D83DwLK6fMY9qcY/TYrp1rOnYKwBQDUj
FMIbaipxss/j8KWEyAwc3dIwJBFCW40yRFR2cg7SCeZ0UJzZEkuDOaIvzkWIGtc3
AqW0R+lvAQ2f+ObbP7iQCGj4HrCgIlPUCDX2SckNuAwaXQIdu5GO+HDjuKb49sw3
8zimt4dAT+OuvZxXDacIhIz53LCJHD/cAyF2CqTdNYpwne892drfiK4FQZ1Jq75Q
4nRedE8YLD2ZwuUALqR1PqHJQKra5hlAhAoITHuTpBG1fggSx6dyj6kSkMR8p6Mb
tADR8onFzUHZgOlkEOjddKaVqAP3z4jW+lfrlk7J/9j5jgRrtLM=
=pM+u
-----END PGP SIGNATURE-----

FreeBSD Errata Notice FreeBSD-EN-23:15.sanitizer

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-EN-23:15.sanitizer Errata Notice
The FreeBSD Project

Topic: Clang sanitizer failure with ASLR enabled

Category: contrib
Module: compiler-rt
Announced: 2023-12-01
Affects: FreeBSD 14.0
Corrected: 2023-11-25 09:05:09 UTC (stable/14, 14.0-STABLE)
2023-12-01 00:38:35 UTC (releng/14.0, 14.0-RELEASE-p1)
2023-11-25 09:05:14 UTC (stable/13, 13.2-STABLE)

For general information regarding FreeBSD Errata Notices and Security
Advisories, including descriptions of the fields above, security
branches, and the following sections, please visit
<URL:https://security.FreeBSD.org/>.

I. Background

Compiler-RT is an implementation of various compiler runtime support routines,
provided by the LLVM project. This library also provides a number of so-called
Sanitizers, which help to catch buffer overruns, thread data races, and so on:
AddressSanitizer, ThreadSanitizer, UndefinedBehaviorSanitizer, and more.

II. Problem Description

Some of the Sanitizers cannot work correctly when ASLR is enabled. Therefore, at
the initialization of such Sanitizers, ASLR is detected via procctl(2). If ASLR
is enabled, it is first disabled, and then the main executable containing the
Sanitizer is re-executed, after printing an appropriate message.

However, the Sanitizers work by intercepting various function calls, and by
mistake the already-intercepted procctl(2) function was used. This causes an
internal error, which usually results in a segfault.

III. Impact

Binaries linked to AddressSanitizer (using -fsanitize=address), MemorySanitizer
(using -fsanitize=memory) or ThreadSanitizer (using -fsanitize=thread) can crash
at startup with a segfault, if ASLR is enabled. Other binaries are not affected.

IV. Workaround

If ASLR is enabled system-wide, the problem can be worked around by running the
specific binary with proccontrol(1), to temporarily disable ASLR for only that
program. For example:

proccontrol -m aslr -s disable /path/to/example_program

V. Solution

Upgrade your system to a supported FreeBSD stable or release / security
branch (releng) dated after the correction date.

No reboot is necessary, but Sanitized binaries must be re-linked, because the
Sanitizer libraries are statically linked in.

Perform one of the following:

1) To update your system via a binary patch:

Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms,
or the i386 platform on FreeBSD 13 and earlier, can be updated via
the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

No reboot is necessary, but Sanitized binaries must be re-linked, because the
Sanitizer libraries are statically linked in.

2) To update your system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

# fetch https://security.FreeBSD.org/patches/EN-23:15/sanitizer.patch
# fetch https://security.FreeBSD.org/patches/EN-23:15/sanitizer.patch.asc
# gpg --verify sanitizer.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile the operating system using buildworld and installworld as
described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>.

VI. Correction details

This issue is corrected as of the corresponding Git commit hash or Subversion
revision number in the following stable and release branches:

Branch/path Hash Revision
- -------------------------------------------------------------------------
stable/14/ 1e4798e9677f stable/14-n265803
releng/14.0/ 78b4c762b20b releng/14.0-n265381
stable/13/ 7c25a53a2cb9 stable/13-n256726
- -------------------------------------------------------------------------

Run the following command to see which files were modified by a
particular commit:

# git show --stat <commit hash>

Or visit the following URL, replacing NNNNNN with the hash:

<URL:https://cgit.freebsd.org/src/commit/?id=NNNNNN>

To determine the commit count in a working tree (for comparison against
nNNNNNN in the table above), run:

# git rev-list --count --first-parent HEAD

VII. References

<URL:https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=275270>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-EN-23:15.sanitizer.asc>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEthUnfoEIffdcgYM7bljekB8AGu8FAmVpPoYACgkQbljekB8A
Gu+z2A//VhWVguaPhfTkV0jRrG/tD1iu+xhM7TSRcnnGYn7IIkzWzHkO5jrP9Oy5
aRueyAVvw048f4unEG36qBM+UO5LSCcDEj3OAhxhJzfTfXcRBYMRuvp5cC+Xjgji
s6S7JlSTeHqJakj6UV58d4elppj5QN1b2IQtwahcwuBtlue4NaOg16z6GFDDbVKo
Db8h+yOyQuwGj7uvahpuHpNB21pMfTwi4IWV2F9QOjQMO/+pcqia+leG53WOsB/A
SFW3zNHdAl+Q7NBq6lRVTqyW69Ouh1gblQ57kMCdzyTF5BSzcDhX5QwiS9t2TIU9
gs2ulNxxIiSPmi7n/ZlDPRyH57C/+h6vSHVeXOVKZhIffrqvpqqhT0WKQfIUnNLb
0uhdmXLdXWWAAk1OvDkBAIiO6C8GxVvgZvHWFhELjnDK6+qmZD7xv3RVpJnRVk9X
//U89b+zGNKhS+JFiTvXY90oUxoE72a9PuqvONZuKMGH+ooL9aRGEJujahCL2Swl
jxymcZHduvsXbnzrmGZr8Lxl4DP+cHD688gc8KOgitb3MCupcx066KmX1Pem7PvX
2AULZrFBDTPEIgf0ZuGt5R3+zd+k/sDlPVGdkLpF1AVOOuwtfton6Vbd5CKDzDLR
0PqGdkk9CLpI0Mm8I1o+v69bopYua1ndo3G2YuKIK7V472sgrRw=
=EPbY
-----END PGP SIGNATURE-----

[USN-6496-2] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmVo1TQFAwAAAAAACgkQZ0GeRcM5nt2w
+wf/RXAupEEmg6+WV5+HOKGbvLLL9D9irsqm0WVdUIBg/X4zJp8Q0vA3l6deCZgqw9aNE6QZuwgN
uS3obu1JwU8vZp1PgaaMtzpsnZUEBDitGDp961rbYtfSW1/6q23cmqA77E9g3kjHgUc9cqfimwt0
Y9Hk+G6vfhvnnltaqf2ISE9kLLDLP/P9bhq/GxYlzbzYtBNiK+NrUo/6QREmqK0UzJbMtDNATeXt
r5nRBPoR7oPP/fZLUjDAYr3wkR2KRKmo6mSalq+sVswot/9qUooSFid1C65glJE1PsNQPb7tA1wP
dP0DnvBtf7UHjhDWE1B5MSqiHJivGZWgSpkk3yFHqA==
=+Thh
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6496-2
November 30, 2023

linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15,
linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-gkeop-5.15
vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-azure-fde: Linux kernel for Microsoft Azure CVM cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gke: Linux kernel for Google Container Engine (GKE) systems
- linux-gkeop: Linux kernel for Google Container Engine (GKE) systems
- linux-azure-5.15: Linux kernel for Microsoft Azure cloud systems
- linux-azure-fde-5.15: Linux kernel for Microsoft Azure CVM cloud systems
- linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gkeop-5.15: Linux kernel for Google Container Engine (GKE) systems

Details:

Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem
discovered that the InfiniBand RDMA driver in the Linux kernel did not
properly check for zero-length STAG or MR registration. A remote attacker
could possibly use this to execute arbitrary code. (CVE-2023-25775)

Yu Hao discovered that the UBI driver in the Linux kernel did not properly
check for MTD with zero erasesize during device attachment. A local
privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-31085)

Manfred Rudigier discovered that the Intel(R) PCI-Express Gigabit (igb)
Ethernet driver in the Linux kernel did not properly validate received
frames that are larger than the set MTU size, leading to a buffer overflow
vulnerability. An attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-45871)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
linux-image-5.15.0-1033-gkeop 5.15.0-1033.39
linux-image-5.15.0-1047-gcp 5.15.0-1047.55
linux-image-5.15.0-1047-gke 5.15.0-1047.52
linux-image-5.15.0-1052-azure 5.15.0-1052.60
linux-image-5.15.0-1052-azure-fde 5.15.0-1052.60.1
linux-image-azure-fde-lts-22.04 5.15.0.1052.60.30
linux-image-azure-lts-22.04 5.15.0.1052.48
linux-image-gcp-lts-22.04 5.15.0.1047.43
linux-image-gke 5.15.0.1047.46
linux-image-gke-5.15 5.15.0.1047.46
linux-image-gkeop 5.15.0.1033.32
linux-image-gkeop-5.15 5.15.0.1033.32

Ubuntu 20.04 LTS:
linux-image-5.15.0-1033-gkeop 5.15.0-1033.39~20.04.1
linux-image-5.15.0-1047-gcp 5.15.0-1047.55~20.04.1
linux-image-5.15.0-1052-azure 5.15.0-1052.60~20.04.1
linux-image-5.15.0-1052-azure-fde 5.15.0-1052.60~20.04.1.1
linux-image-azure 5.15.0.1052.60~20.04.41
linux-image-azure-cvm 5.15.0.1052.60~20.04.41
linux-image-azure-fde 5.15.0.1052.60~20.04.1.30
linux-image-gcp 5.15.0.1047.55~20.04.1
linux-image-gkeop-5.15 5.15.0.1033.39~20.04.29

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6496-2
https://ubuntu.com/security/notices/USN-6496-1
CVE-2023-25775, CVE-2023-31085, CVE-2023-45871

Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1052.60
https://launchpad.net/ubuntu/+source/linux-azure-fde/5.15.0-1052.60.1
https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1047.55
https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1047.52
https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1033.39
https://launchpad.net/ubuntu/+source/linux-azure-5.15/5.15.0-1052.60~20.04.1

https://launchpad.net/ubuntu/+source/linux-azure-fde-5.15/5.15.0-1052.60~20.04.1.1
https://launchpad.net/ubuntu/+source/linux-gcp-5.15/5.15.0-1047.55~20.04.1
https://launchpad.net/ubuntu/+source/linux-gkeop-5.15/5.15.0-1033.39~20.04.1