Thursday, April 11, 2024

Re: Fedora Linux 40 Go/No-Go Meeting: 2024-11-04

REMINDER: The Fedora Linux 40 Go/No-Go meeting is scheduled for today, 11th April @ 1700 UTC in in #meeting:fedoraproject.org channel on Matrix.


Aoife Moloney
Fedora Operations Architect

On Mon, Apr 8, 2024, 10:23 PM Aoife Moloney <amoloney@redhat.com> wrote:
Happy Monday folks!

On Thursday 11th April, the Fedora Linux 40 Final Go/No-Go meeting[1] will be held at 1700 UTC in #meeting:fedoraproject.org channel on Matrix.

At this time, we will determine the status of the F40 Final release for the 16th April, which is the early target date[2]. For more information about the Go/No-Go meeting, see the wiki[3].


[1] https://calendar.fedoraproject.org/meeting/10787/
[2] https://fedorapeople.org/groups/schedule/f-40/f-40-key-tasks.html
[3] https://fedoraproject.org/wiki/Go_No_Go_Meeting


--

Aoife Moloney

Fedora Operations Architect

Fedora Project

Matrix: @amoloney:fedora.im

IRC: amoloney


[USN-6728-2] Squid regression

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmYX1xsACgkQZWnYVadE
vpPP2BAAj5Wjc9yqAKoocH0MHCOL5TfIczZXF991Wm+gJpMMpfkfzKaB2Tzx4CIw
o9n09Mj9YLu/dj+vDl0//2I9o3YxYSCzHQijuOc/HJFALwWs3lHwGNa9OeFfsfug
mfsu/7Bt+rNl7B94aSq/xpWzGY9G7GY56TN1vPFks8CwqOCsLwZ4jMjVcJ6Ptg2P
5AYSyMqOaMveyw6O6c7FOWNDmGgfCY6bLy8pNhVGzdElF855pb4IjZyoV2xQPJ8I
0iTlSUmJafEhVWVMf9n9bb/rYlL06GL17vqm8/NOTik3Pm6OpPDZVPcDlG0yPL3L
6zxgIa1D6ChUQZwuVXRPPIXx+GQMtOlZuTk+ZYp+PH3UP9XI+m1RXJfJZbtk08ZH
zXSasVgePKmWL5GiTSZKksfG5A54IfVbhsHwpz2pBKWdlooklPl+VAztHBYuymd+
Jr52PBp0rdTATqtX5uus73dKTwEPelQJ+DFZLCkkqfCKJj1L2Ally5EgRE39SZJb
b+yd8kFqhAfZfjnti7R1lz1S6pM9TnXtMtjPmGf53m2FqaFQYp2eulAmBlIY4KpN
8LwqcOnwmhibiirTbnoArGVniP2mkYGQ88EUN5rE4emZnCOTk1AUMO+dgyuzFA1V
bSVQWmdjOQq8bglm32pYHQ60it3qdZxianRFxxxeHT/zNYMQcqs=
=yU6f
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6728-2
April 11, 2024

squid regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

USN-6728-1 introduced a regression in Squid.

Software Description:
- squid: Web proxy cache server

Details:

USN-6728-1 fixed vulnerabilities in Squid. The fix for CVE-2023-5824 caused
Squid to crash in certain environments on Ubuntu 20.04 LTS. The problematic
fix has been reverted pending further investigation.

We apologize for the inconvenience.

Original advisory details:

Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)
Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. (CVE-2023-5824)
Joshua Rogers discovered that Squid incorrectly handled Cache Manager error
responses. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-23638)
Joshua Rogers discovered that Squid incorrectly handled the HTTP Chunked
decoder. A remote attacker could possibly use this issue to cause Squid to
stop responding, resulting in a denial of service. (CVE-2024-25111)
Joshua Rogers discovered that Squid incorrectly handled HTTP header
parsing. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-25617)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
squid 4.10-1ubuntu1.11

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6728-2
https://ubuntu.com/security/notices/USN-6728-1
https://launchpad.net/bugs/2060880

Package Information:
https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.11

Wednesday, April 10, 2024

[USN-6728-1] Squid vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmYWx34ACgkQZWnYVadE
vpOgZRAAiRzOpGON2rMCMVLey74cD67SpbyBJEYa9y/lEMpFj5rOmKy02scFFjKV
GlDW0Ba8RtRXa+bTOoiQQCWw5NXDHQVQgN+k2b83lJ31CqyzHpjCnoPpTI/UhU3s
+YlF4IF+gWyctndDvkJM217PaAE6uhx+4Ea1FywIP4A/GZPu0PNaCSxE6dUYZGu+
27OdvTXfbrxmb+ZI1jW14rW3W0xPDN18Mh9rYtDR4ENEIwQKL5sy/WY7i5kvN3Bq
oPlbnGnSgaKtV3xejnHQzTOEGpHybeT4r9uAHjG/3lESdBhpl87C5T7Rse14ZTDd
ech129zEd1d5wuxJPuDoFV5rFCF96vyLpSzSp7SE5dMlTajWCbj8Y6TqGda9mOYD
k5PnZUUiQ+HQ5++lt/pU6yhCjSnvodMMZ3+JN9VB8fVcQlk6gzqvGF501mu68qaJ
x96d72D8avoBpORr4vFKmHwiJ5BcWJJJIgUlZcj46oCVEL5dJYtsk79BiESoDe+Q
Igr0OlxotP+1WQaeJEWiZSC3vW72iOQXa9X36rIiaPSIPWXeHtSUMqie2q5hSJXQ
7QzVqbAkPE/lGSzhGrtUjIEdafh/UWWrZ25snJa6SC8WzxUYDlVHxghoxWnQM0sM
dOcgPvHpY/7b/ZFm+OJHUKv+a8CzCS/T6vsBANEwQ8C2nKWfiq4=
=FWkE
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6728-1
April 10, 2024

squid vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in Squid.

Software Description:
- squid: Web proxy cache server

Details:

Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)

Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. (CVE-2023-5824)

Joshua Rogers discovered that Squid incorrectly handled Cache Manager error
responses. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-23638)

Joshua Rogers discovered that Squid incorrectly handled the HTTP Chunked
decoder. A remote attacker could possibly use this issue to cause Squid to
stop responding, resulting in a denial of service. (CVE-2024-25111)

Joshua Rogers discovered that Squid incorrectly handled HTTP header
parsing. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-25617)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
squid 6.1-2ubuntu1.3

Ubuntu 22.04 LTS:
squid 5.7-0ubuntu0.22.04.4

Ubuntu 20.04 LTS:
squid 4.10-1ubuntu1.10

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6728-1
CVE-2023-49288, CVE-2023-5824, CVE-2024-23638, CVE-2024-25111,
CVE-2024-25617

Package Information:
https://launchpad.net/ubuntu/+source/squid/6.1-2ubuntu1.3
https://launchpad.net/ubuntu/+source/squid/5.7-0ubuntu0.22.04.4
https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.10

[USN-6727-1] NSS vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmYWrrQACgkQZWnYVadE
vpPFEw/9Et0IH3v1bCIv7yuXTaATQcrDiadoXiexEXsz1PuP5xmwQqpCZnAsTevr
cJfLTsrQ17v8OXs8JnvCvBjsKo9Zm58pVoFnA25tfgT2uOtxSY7Nv0TBh5nd8/iW
9VwYJdcKqEnwfQpS44G2WaR8Rs9XBGc8bEm1ZzAjQzJcgKRfnEx8xP7+Sd25zRei
493I1eRinf8ECwZowKrO5MW9G0CC5vlk0bNnbAQmpFRrsO3rX+hmRDqMu690ll2q
SVIVCUrXZyN9MZJaL19UdSrmKMhKISYNq4x0MBFEVomlQAMNteslKlxP3k8H6eDn
V1+3RO1Z9UnoRuyKVURJb5uE6oIorDR1RDeqqHpXkExu05Wu3P9TjA/6KFk44DL/
QzlX3fOKXKPSUJEBA3tODuEa/UEsN2m6jP2+jjnMAlEPBwZDtf18J7fHgW/2WkLb
3MeOneUzdOWT5ncNp6QviZpEgOZ66OBBzqERyEqvTY7EEJLMDuq72if24EYO/rmD
bSGni+JlrEUPTP75eCLix7vPJYCz2DuZmtkEkLoXvh+pCYQFo0xj26bTNywYvZzX
lcKI2Mzr0Bpl1fX54zr1cOn6QLV56n1vToJ+ETh7NZQ96KUSUtRhsFprWuyJJNDa
sSx6q5Zi3Tw1LocvuqEAgO4e1zaDSo1bZhMsNEg0Uq/zIEH3Seg=
=8V5M
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6727-1
April 10, 2024

nss vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in NSS.

Software Description:
- nss: Network Security Service library

Details:

It was discovered that NSS incorrectly handled padding when checking PKCS#1
certificates. A remote attacker could possibly use this issue to perform
Bleichenbacher-like attacks and recover private data. This issue only
affected Ubuntu 20.04 LTS. (CVE-2023-4421)

It was discovered that NSS had a timing side-channel when performing RSA
decryption. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-5388)

It was discovered that NSS had a timing side-channel when using certain
NIST curves. A remote attacker could possibly use this issue to recover
private data. (CVE-2023-6135)

The NSS package contained outdated CA certificates. This update refreshes
the NSS package to version 3.98 which includes the latest CA certificate
bundle and other security improvements.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
libnss3 2:3.98-0ubuntu0.23.10.1

Ubuntu 22.04 LTS:
libnss3 2:3.98-0ubuntu0.22.04.1

Ubuntu 20.04 LTS:
libnss3 2:3.98-0ubuntu0.20.04.1

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References:
https://ubuntu.com/security/notices/USN-6727-1
CVE-2023-4421, CVE-2023-5388, CVE-2023-6135

Package Information:
https://launchpad.net/ubuntu/+source/nss/2:3.98-0ubuntu0.23.10.1
https://launchpad.net/ubuntu/+source/nss/2:3.98-0ubuntu0.22.04.1
https://launchpad.net/ubuntu/+source/nss/2:3.98-0ubuntu0.20.04.1

[USN-6719-2] util-linux vulnerability

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmYWkokACgkQZWnYVadE
vpO40g/+JR9aFZ0FdSaiH2UmpFDVYksw33TEExYXVzXlCl1Y5XnN5FCzDacD/8uF
MrEGyYyLpz/ooNamPtRh1wRJ6g/JGrLJJyNa/ppIXjbyGo22OGQA5j5B8QMBoJUE
Hsc4pxSTlyPWyEU7AYL2NyZYL0k7sTKQeOxcRgjkYG+jA/BURwIvzlMJFhaIj7R2
zOOBv7RbBGelWU4KjqmYvIxwz/OTcmtDi1i3QX3OZW3aCO7pVRXGkpRgaOPe/y/6
YOt5mUqwghIkt8eFI63gWAH0XjzBNC3D9qVPg6TP1bOlqCqpAfjBVY/H4ZgvENeX
EvKF7og654Llm57Y1JJWrXW7vShLGpgZ6gT4Lt3EcCL99K6gNqIquxfSILKGCsEZ
7+xxUMnOlxSlQBI5uggbzHtb8chU9f5+Hn5fKv+JcMJv9E9w4RxL+dj25GHwGXgq
Cs9zqHdPebSbHz961G6/TQl3/OlrloLrKLd8hRpUtcJ5TTvekle3j6qE/307tkEC
MuYAXEvRszWrtNrsIfQwYhcAgU5amG0HrrOqcItlGjmNEywqqj98G09BypX2X77w
ikCqji2ncsG2eLfcNt2MQsbnRx3c/YeK5tqlLCPgaDbwphsU+At/jk/JOQYOpGXv
umtYemTI+5SAVvcLgm2sOtsVMh3hQjSfgLyM98nmHgHwOquYH4I=
=53Gz
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6719-2
April 10, 2024

util-linux vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

util-linux could be made to expose sensitive information.

Software Description:
- util-linux: miscellaneous system utilities

Details:

USN-6719-1 fixed a vulnerability in util-linux. Unfortunately, it was
discovered that the fix did not fully address the issue. This update
removes the setgid permission bit from the wall and write utilities.

Original advisory details:

Skyler Ferrante discovered that the util-linux wall command did not filter
escape sequences from command line arguments. A local attacker could
possibly use this issue to obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
util-linux 2.39.1-4ubuntu2.2

Ubuntu 22.04 LTS:
util-linux 2.37.2-4ubuntu3.4

Ubuntu 20.04 LTS:
util-linux 2.34-0.1ubuntu9.6

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6719-2
https://ubuntu.com/security/notices/USN-6719-1
CVE-2024-28085

Package Information:
https://launchpad.net/ubuntu/+source/util-linux/2.39.1-4ubuntu2.2
https://launchpad.net/ubuntu/+source/util-linux/2.37.2-4ubuntu3.4
https://launchpad.net/ubuntu/+source/util-linux/2.34-0.1ubuntu9.6

OpenSMTPD 7.5.0p0 Released

OpenSMTPD is a FREE implementation of the SMTP protocol with some common
extensions. It allows ordinary machines to exchange e-mails with systems
speaking the SMTP protocol. It implements a fairly large part of RFC5321
and can already cover a large range of use-cases.

It runs on OpenBSD, NetBSD, FreeBSD, DragonFlyBSD, Linux and OSX.

The archives are now available from the main site at www.OpenSMTPD.org

We would like to thank the OpenSMTPD community for their help in testing
the snapshots, reporting bugs, contributing code and packaging for other
systems.

This is a major release with multiple bug fixes and new features.


Dependencies note:
==================

This release builds with LibreSSL, or OpenSSL >= 1.1.

It's preferable to depend on LibreSSL as OpenSMTPD is written and tested
with that dependency. OpenSSL library is considered as a best effort
target TLS library and provided as a commodity, LibreSSL has become our
target TLS library.


Changes in this release:
========================

- Added support for RFC 7505 "Null MX" handling and treat an MX of
"localhost" as it were a "Null MX".

- Allow inline tables and filter listings in smtpd.conf(5) to span
over multiple lines.

- Enabled DSN for the implicit socket too.

- Added the `no-dsn' option for listen on socket too.

- Reject headers that start with a space or a tab.

- Fixed parsing of the ORCPT parameter.

- Fixed table lookups of IPv6 addresses.

- Fixed handling of escape characters in To, From and Cc headers.

- Run LMTP deliveries as the recipient user again.

- Disallow custom commands and file reading in root's .forward file.

- Do not process other users .forward files when an alternate
delivery user is provided in a dispatcher.

- Unify the table(5) parser used in smtpd(8) and makemap(8).

- Allow to use table(5) mappings on various match constraints.

Portability fixes:

- re-add ASR_IPV4_BEFORE_IPV6 compile-time knob to prefer connecting
to IPv6 instead of IPv4.

- update asr(3) and imsg with OpenBSD.

- fixed rpath handling on NetBSD in the configure.


Checksums:
==========

SHA256 (opensmtpd-7.5.0p0.tar.gz) =
84f5c1393c0c1becc72ceea971e0abd7075b2ca7e4e1f8909b83edfd8de0c39c


Verify:
=======

Starting with version 5.7.1, releases are signed with signify(1).

You can obtain the public key from our website, check with our community
that it has not been altered on its way to your machine.

$ wget https://www.opensmtpd.org/archives/opensmtpd-20181026.pub

Once you are confident the key is correct, you can verify the release as
described below:

1. download both release tarball and matching signature file to same directory:

$ wget https://www.opensmtpd.org/archives/opensmtpd-7.5.0p0.sum.sig
$ wget https://www.opensmtpd.org/archives/opensmtpd-7.5.0p0.tar.gz


2. use `signify` to verify that signature file is properly signed and that the
checksum matches the release tarball you downloaded:

$ signify -C -e -p opensmtpd-20181026.pub -x opensmtpd-7.5.0p0.sum.sig
Signature Verified
opensmtpd-7.5.0p0.tar.gz: OK


If you don't get an OK message, then something is not right and you should not
install without first understanding why it failed.


Support:
========

You are encouraged to register to our general purpose mailing-list:
http://www.opensmtpd.org/list.html

The "Official" IRC channel for the project is at:
#opensmtpd @ irc.libera.chat


Support us:
===========

The project is maintained by volunteers, you can support us by:

- donating time to help test development branch during development cycle
- donating money to either one of the OpenBSD or OpenSMTPD project
- sponsoring developers through direct donations or patreon
- sponsoring developers through contracts to write features

Get in touch with us by e-mail or on IRC for more informations.


Reporting Bugs:
===============

Please read http://www.opensmtpd.org/report.html
Security bugs should be reported directly to security@opensmtpd.org
Other bugs may be reported to bugs@opensmtpd.org

Tuesday, April 9, 2024

[USN-6721-2] X.Org X Server regression

==========================================================================
Ubuntu Security Notice USN-6721-2
April 09, 2024

xorg-server, xwayland regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)

Summary:

A regression was fixed in X.Org X Server.

Software Description:
- xorg-server: X.Org X11 server
- xwayland: X server for running X clients under Wayland

Details:

USN-6721-1 fixed vulnerabilities in X.Org X Server. That fix was incomplete
resulting in a regression. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that X.Org X Server incorrectly handled certain data.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2024-31080, CVE-2024-31081, CVE-2024-31082)

It was discovered that X.Org X Server incorrectly handled certain glyphs.
An attacker could possibly use this issue to cause a crash or expose sensitive
information. (CVE-2024-31083)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
xserver-xorg-core 2:21.1.7-3ubuntu2.9
xwayland 2:23.2.0-1ubuntu0.6

Ubuntu 22.04 LTS:
xserver-xorg-core 2:21.1.4-2ubuntu1.7~22.04.10
xwayland 2:22.1.1-1ubuntu0.13

Ubuntu 20.04 LTS:
xserver-xorg-core 2:1.20.13-1ubuntu1~20.04.17
xwayland 2:1.20.13-1ubuntu1~20.04.17

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
xserver-xorg-core 2:1.19.6-1ubuntu4.15+esm8
xwayland 2:1.19.6-1ubuntu4.15+esm8

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
xserver-xorg-core 2:1.18.4-0ubuntu0.12+esm13
xwayland 2:1.18.4-0ubuntu0.12+esm13

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
xserver-xorg-core 2:1.15.1-0ubuntu2.11+esm12

After a standard system update you need to restart -APP- to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6721-2
https://ubuntu.com/security/notices/USN-6721-1
https://launchpad.net/bugs/2060354

Package Information:
https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.7-3ubuntu2.9
https://launchpad.net/ubuntu/+source/xwayland/2:23.2.0-1ubuntu0.6
https://launchpad.net/ubuntu/+source/xorg-server/2:21.1.4-2ubuntu1.7~22.04.10
https://launchpad.net/ubuntu/+source/xwayland/2:22.1.1-1ubuntu0.13
https://launchpad.net/ubuntu/+source/xorg-server/2:1.20.13-1ubuntu1~20.04.17

[USN-6701-4] Linux kernel (Azure) vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmYVTLAFAwAAAAAACgkQZ0GeRcM5nt0u
oQf/Q2QO9TXvWE9rBPWo4y7kay7ABXA2yPbRXJxAdzr8MahvjROC0MdmGuQ8nqMKyplPxucD/i57
FlEBg3it/R9cZf0YS86E/D5VMr/MizGs1zHobQv0hd+/+pTrhO6ceKwirNncnCfngmuND/3m7lGC
R3CzAUVULB+GasqO8tH717D1ZC6i6XfyuTqPYFlhBi46mRqP4L+sZwl7fUGnoyjILLU7TMF+OX4n
qzQ/Q8j++7d9XVIjP6hpnj1923GUs52uEtb6PLBYA4t3qko+ejYWjPAyz51nr3Fa3O9v5GsTTtFV
FwjazNGjTrDJAWFZetCLREy3KmD6c7YwbnzlQbvH8A==
=Ei04
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6701-4
April 09, 2024

linux-azure vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS (Available with Ubuntu Pro)

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems

Details:

Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did
not properly perform permissions checks when handling HCI sockets. A
physically proximate attacker could use this to cause a denial of service
(bluetooth communication). (CVE-2023-2002)

It was discovered that the NVIDIA Tegra XUSB pad controller driver in the
Linux kernel did not properly handle return values in certain error
conditions. A local attacker could use this to cause a denial of service
(system crash). (CVE-2023-23000)

It was discovered that Spectre-BHB mitigations were missing for Ampere
processors. A local attacker could potentially use this to expose sensitive
information. (CVE-2023-3006)

It was discovered that the ext4 file system implementation in the Linux
kernel did not properly handle block device modification while it is
mounted. A privileged attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2023-34256)

Eric Dumazet discovered that the netfilter subsystem in the Linux kernel
did not properly handle DCCP conntrack buffers in certain situations,
leading to an out-of-bounds read vulnerability. An attacker could possibly
use this to expose sensitive information (kernel memory). (CVE-2023-39197)

It was discovered that the Siano USB MDTV receiver device driver in the
Linux kernel did not properly handle device initialization failures in
certain situations, leading to a use-after-free vulnerability. A physically
proximate attacker could use this cause a denial of service (system crash).
(CVE-2023-4132)

Pratyush Yadav discovered that the Xen network backend implementation in
the Linux kernel did not properly handle zero length data request, leading
to a null pointer dereference vulnerability. An attacker in a guest VM
could possibly use this to cause a denial of service (host domain crash).
(CVE-2023-46838)

It was discovered that a race condition existed in the AppleTalk networking
subsystem of the Linux kernel, leading to a use-after-free vulnerability. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2023-51781)

Alon Zahavi discovered that the NVMe-oF/TCP subsystem of the Linux kernel
did not properly handle connect command payloads in certain situations,
leading to an out-of-bounds read vulnerability. A remote attacker could use
this to expose sensitive information (kernel memory). (CVE-2023-6121)

It was discovered that the ext4 file system implementation in the Linux
kernel did not properly handle the remount operation in certain cases,
leading to a use-after-free vulnerability. A local attacker could use this
to cause a denial of service (system crash) or possibly expose sensitive
information. (CVE-2024-0775)

Notselwyn discovered that the netfilter subsystem in the Linux kernel did
not properly handle verdict parameters in certain cases, leading to a use-
after-free vulnerability. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2024-1086)

It was discovered that a race condition existed in the SCSI Emulex
LightPulse Fibre Channel driver in the Linux kernel when unregistering FCF
and re-scanning an HBA FCF table, leading to a null pointer dereference
vulnerability. A local attacker could use this to cause a denial of service
(system crash). (CVE-2024-24855)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
linux-image-4.15.0-1175-azure 4.15.0-1175.190~14.04.1
linux-image-azure 4.15.0.1175.141

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6701-4
https://ubuntu.com/security/notices/USN-6701-1
CVE-2023-2002, CVE-2023-23000, CVE-2023-3006, CVE-2023-34256,
CVE-2023-39197, CVE-2023-4132, CVE-2023-46838, CVE-2023-51781,
CVE-2023-6121, CVE-2024-0775, CVE-2024-1086, CVE-2024-24855

[USN-6725-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmYVTJkFAwAAAAAACgkQZ0GeRcM5nt1V
VAgAsbVug7IlShvQMcVj/MNerxuDbcFNJ6GbC4JFrLEjuAsFoPlG/LLkwK8jQWub+nXmps40LUX9
uFpSaxCqPd26DS8RiQ+rlWYsd4PNH9Zkz4wJ1uenvRh0uVsYv2K4CWnQLWp7UnkX59mMSphDMedP
YAotQm35k9FmPpWi2ZidF+T0Crmxz+urL8wE47RpL+L3uv7GebzxmrqazPKnnHK2JiXlTlSbhqXI
fSvMflhUA0wkvLVshlL6Q504057d/O/kTkoQn0VCx1TjVk9u+GoT6n/Mf1smgd03uwEIucEeJLnQ
G3MYIZbCIKIFRDt7DJfgoVx3dn4PcCYYdv3CdY8u5Q==
=Rjut
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6725-1
April 09, 2024

linux, linux-azure, linux-azure-5.15, linux-azure-fde,
linux-azure-fde-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop,
linux-gkeop-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15,
linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency,
linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15,
linux-raspi vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-azure-fde: Linux kernel for Microsoft Azure CVM cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gke: Linux kernel for Google Container Engine (GKE) systems
- linux-gkeop: Linux kernel for Google Container Engine (GKE) systems
- linux-ibm: Linux kernel for IBM cloud systems
- linux-intel-iotg: Linux kernel for Intel IoT platforms
- linux-kvm: Linux kernel for cloud environments
- linux-lowlatency: Linux low latency kernel
- linux-nvidia: Linux kernel for NVIDIA systems
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-raspi: Linux kernel for Raspberry Pi systems
- linux-azure-5.15: Linux kernel for Microsoft Azure cloud systems
- linux-azure-fde-5.15: Linux kernel for Microsoft Azure CVM cloud systems
- linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gkeop-5.15: Linux kernel for Google Container Engine (GKE) systems
- linux-hwe-5.15: Linux hardware enablement (HWE) kernel
- linux-ibm-5.15: Linux kernel for IBM cloud systems
- linux-intel-iotg-5.15: Linux kernel for Intel IoT platforms
- linux-lowlatency-hwe-5.15: Linux low latency kernel
- linux-oracle-5.15: Linux kernel for Oracle Cloud systems

Details:

Chih-Yen Chang discovered that the KSMBD implementation in the Linux kernel
did not properly validate certain data structure fields when parsing lease
contexts, leading to an out-of-bounds read vulnerability. A remote attacker
could use this to cause a denial of service (system crash) or possibly
expose sensitive information. (CVE-2023-1194)

Quentin Minster discovered that a race condition existed in the KSMBD
implementation in the Linux kernel, leading to a use-after-free
vulnerability. A remote attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2023-32254)

It was discovered that a race condition existed in the KSMBD implementation
in the Linux kernel when handling session connections, leading to a use-
after-free vulnerability. A remote attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2023-32258)

It was discovered that the KSMBD implementation in the Linux kernel did not
properly validate buffer sizes in certain operations, leading to an integer
underflow and out-of-bounds read vulnerability. A remote attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information. (CVE-2023-38427)

Chih-Yen Chang discovered that the KSMBD implementation in the Linux kernel
did not properly validate SMB request protocol IDs, leading to a out-of-
bounds read vulnerability. A remote attacker could possibly use this to
cause a denial of service (system crash). (CVE-2023-38430)

Chih-Yen Chang discovered that the KSMBD implementation in the Linux kernel
did not properly validate packet header sizes in certain situations,
leading to an out-of-bounds read vulnerability. A remote attacker could use
this to cause a denial of service (system crash) or possibly expose
sensitive information. (CVE-2023-38431)

It was discovered that the KSMBD implementation in the Linux kernel did not
properly handle session setup requests, leading to an out-of-bounds read
vulnerability. A remote attacker could use this to expose sensitive
information. (CVE-2023-3867)

Pratyush Yadav discovered that the Xen network backend implementation in
the Linux kernel did not properly handle zero length data request, leading
to a null pointer dereference vulnerability. An attacker in a guest VM
could possibly use this to cause a denial of service (host domain crash).
(CVE-2023-46838)

It was discovered that the IPv6 implementation of the Linux kernel did not
properly manage route cache memory usage. A remote attacker could use this
to cause a denial of service (memory exhaustion). (CVE-2023-52340)

It was discovered that the device mapper driver in the Linux kernel did not
properly validate target size during certain memory allocations. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2023-52429, CVE-2024-23851)

Yang Chaoming discovered that the KSMBD implementation in the Linux kernel
did not properly validate request buffer sizes, leading to an out-of-bounds
read vulnerability. An attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2024-22705)

Chenyuan Yang discovered that the btrfs file system in the Linux kernel did
not properly handle read operations on newly created subvolumes in certain
conditions. A local attacker could use this to cause a denial of service
(system crash). (CVE-2024-23850)

It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Architecture specifics;
- Block layer;
- Cryptographic API;
- Android drivers;
- EDAC drivers;
- GPU drivers;
- Media drivers;
- Multifunction device drivers;
- MTD block device drivers;
- Network drivers;
- NVME drivers;
- TTY drivers;
- Userspace I/O drivers;
- EFI Variable file system;
- F2FS file system;
- GFS2 file system;
- SMB network file system;
- BPF subsystem;
- IPv6 Networking;
- Network Traffic Control;
- AppArmor security module;
(CVE-2023-52463, CVE-2023-52445, CVE-2023-52462, CVE-2023-52609,
CVE-2023-52448, CVE-2023-52457, CVE-2023-52464, CVE-2023-52456,
CVE-2023-52454, CVE-2023-52438, CVE-2023-52480, CVE-2023-52443,
CVE-2023-52442, CVE-2024-26631, CVE-2023-52439, CVE-2023-52612,
CVE-2024-26598, CVE-2024-26586, CVE-2024-26589, CVE-2023-52444,
CVE-2023-52436, CVE-2024-26633, CVE-2024-26597, CVE-2023-52458,
CVE-2024-26591, CVE-2023-52449, CVE-2023-52467, CVE-2023-52441,
CVE-2023-52610, CVE-2023-52451, CVE-2023-52469, CVE-2023-52470)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
linux-image-5.15.0-102-generic 5.15.0-102.112
linux-image-5.15.0-102-generic-64k 5.15.0-102.112
linux-image-5.15.0-102-generic-lpae 5.15.0-102.112
linux-image-5.15.0-102-lowlatency 5.15.0-102.112
linux-image-5.15.0-102-lowlatency-64k 5.15.0-102.112
linux-image-5.15.0-1040-gkeop 5.15.0-1040.46
linux-image-5.15.0-1048-nvidia 5.15.0-1048.48
linux-image-5.15.0-1048-nvidia-lowlatency 5.15.0-1048.48
linux-image-5.15.0-1050-ibm 5.15.0-1050.53
linux-image-5.15.0-1050-raspi 5.15.0-1050.53
linux-image-5.15.0-1052-intel-iotg 5.15.0-1052.58
linux-image-5.15.0-1054-gke 5.15.0-1054.59
linux-image-5.15.0-1054-kvm 5.15.0-1054.59
linux-image-5.15.0-1055-gcp 5.15.0-1055.63
linux-image-5.15.0-1055-oracle 5.15.0-1055.61
linux-image-5.15.0-1060-azure 5.15.0-1060.69
linux-image-5.15.0-1060-azure-fde 5.15.0-1060.69.1
linux-image-azure-fde-lts-22.04 5.15.0.1060.69.38
linux-image-azure-lts-22.04 5.15.0.1060.58
linux-image-gcp-lts-22.04 5.15.0.1055.51
linux-image-generic 5.15.0.102.99
linux-image-generic-64k 5.15.0.102.99
linux-image-generic-lpae 5.15.0.102.99
linux-image-gke 5.15.0.1054.53
linux-image-gke-5.15 5.15.0.1054.53
linux-image-gkeop 5.15.0.1040.39
linux-image-gkeop-5.15 5.15.0.1040.39
linux-image-ibm 5.15.0.1050.46
linux-image-intel-iotg 5.15.0.1052.52
linux-image-kvm 5.15.0.1054.50
linux-image-lowlatency 5.15.0.102.98
linux-image-lowlatency-64k 5.15.0.102.98
linux-image-nvidia 5.15.0.1048.48
linux-image-nvidia-lowlatency 5.15.0.1048.48
linux-image-oracle-lts-22.04 5.15.0.1055.51
linux-image-raspi 5.15.0.1050.48
linux-image-raspi-nolpae 5.15.0.1050.48
linux-image-virtual 5.15.0.102.99

Ubuntu 20.04 LTS:
linux-image-5.15.0-102-generic 5.15.0-102.112~20.04.1
linux-image-5.15.0-102-generic-64k 5.15.0-102.112~20.04.1
linux-image-5.15.0-102-generic-lpae 5.15.0-102.112~20.04.1
linux-image-5.15.0-102-lowlatency 5.15.0-102.112~20.04.1
linux-image-5.15.0-102-lowlatency-64k 5.15.0-102.112~20.04.1
linux-image-5.15.0-1040-gkeop 5.15.0-1040.46~20.04.1
linux-image-5.15.0-1050-ibm 5.15.0-1050.53~20.04.1
linux-image-5.15.0-1052-intel-iotg 5.15.0-1052.58~20.04.1
linux-image-5.15.0-1055-gcp 5.15.0-1055.63~20.04.1
linux-image-5.15.0-1055-oracle 5.15.0-1055.61~20.04.1
linux-image-5.15.0-1060-azure 5.15.0-1060.69~20.04.1
linux-image-5.15.0-1060-azure-fde 5.15.0-1060.69~20.04.1.1
linux-image-azure 5.15.0.1060.69~20.04.1
linux-image-azure-cvm 5.15.0.1060.69~20.04.1
linux-image-azure-fde 5.15.0.1060.69~20.04.1.39
linux-image-gcp 5.15.0.1055.63~20.04.1
linux-image-generic-64k-hwe-20.04 5.15.0.102.112~20.04.1
linux-image-generic-hwe-20.04 5.15.0.102.112~20.04.1
linux-image-generic-lpae-hwe-20.04 5.15.0.102.112~20.04.1
linux-image-gkeop-5.15 5.15.0.1040.46~20.04.36
linux-image-ibm 5.15.0.1050.53~20.04.1
linux-image-intel 5.15.0.1052.58~20.04.1
linux-image-intel-iotg 5.15.0.1052.58~20.04.1
linux-image-lowlatency-64k-hwe-20.04 5.15.0.102.112~20.04.1
linux-image-lowlatency-hwe-20.04 5.15.0.102.112~20.04.1
linux-image-oem-20.04 5.15.0.102.112~20.04.1
linux-image-oem-20.04b 5.15.0.102.112~20.04.1
linux-image-oem-20.04c 5.15.0.102.112~20.04.1
linux-image-oem-20.04d 5.15.0.102.112~20.04.1
linux-image-oracle 5.15.0.1055.61~20.04.1
linux-image-virtual-hwe-20.04 5.15.0.102.112~20.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6725-1
CVE-2023-1194, CVE-2023-32254, CVE-2023-32258, CVE-2023-38427,
CVE-2023-38430, CVE-2023-38431, CVE-2023-3867, CVE-2023-46838,
CVE-2023-52340, CVE-2023-52429, CVE-2023-52436, CVE-2023-52438,
CVE-2023-52439, CVE-2023-52441, CVE-2023-52442, CVE-2023-52443,
CVE-2023-52444, CVE-2023-52445, CVE-2023-52448, CVE-2023-52449,
CVE-2023-52451, CVE-2023-52454, CVE-2023-52456, CVE-2023-52457,
CVE-2023-52458, CVE-2023-52462, CVE-2023-52463, CVE-2023-52464,
CVE-2023-52467, CVE-2023-52469, CVE-2023-52470, CVE-2023-52480,
CVE-2023-52609, CVE-2023-52610, CVE-2023-52612, CVE-2024-22705,
CVE-2024-23850, CVE-2024-23851, CVE-2024-24860, CVE-2024-26586,
CVE-2024-26589, CVE-2024-26591, CVE-2024-26597, CVE-2024-26598,
CVE-2024-26631, CVE-2024-26633

Package Information:
https://launchpad.net/ubuntu/+source/linux/5.15.0-102.112
https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1060.69
https://launchpad.net/ubuntu/+source/linux-azure-fde/5.15.0-1060.69.1
https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1055.63
https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1054.59
https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1040.46
https://launchpad.net/ubuntu/+source/linux-ibm/5.15.0-1050.53
https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1052.58
https://launchpad.net/ubuntu/+source/linux-kvm/5.15.0-1054.59
https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-102.112
https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1048.48
https://launchpad.net/ubuntu/+source/linux-oracle/5.15.0-1055.61
https://launchpad.net/ubuntu/+source/linux-raspi/5.15.0-1050.53
https://launchpad.net/ubuntu/+source/linux-azure-5.15/5.15.0-1060.69~20.04.1

https://launchpad.net/ubuntu/+source/linux-azure-fde-5.15/5.15.0-1060.69~20.04.1.1
https://launchpad.net/ubuntu/+source/linux-gcp-5.15/5.15.0-1055.63~20.04.1
https://launchpad.net/ubuntu/+source/linux-gkeop-5.15/5.15.0-1040.46~20.04.1
https://launchpad.net/ubuntu/+source/linux-hwe-5.15/5.15.0-102.112~20.04.1
https://launchpad.net/ubuntu/+source/linux-ibm-5.15/5.15.0-1050.53~20.04.1

https://launchpad.net/ubuntu/+source/linux-intel-iotg-5.15/5.15.0-1052.58~20.04.1

https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-5.15/5.15.0-102.112~20.04.1

https://launchpad.net/ubuntu/+source/linux-oracle-5.15/5.15.0-1055.61~20.04.1

[USN-6726-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmYVTKcFAwAAAAAACgkQZ0GeRcM5nt3k
SQf/VOZdgCSZ6VIFixsl0D54EUCzA1C5aoqSWP4pCw7CdrF2nvqpd2Do0rEWfSL5k3bopRdJ02HB
zgtmmYxk8IJAvKVYTLav5NW/50MDtsRvPu5e/9dnXHUrxdPZkPYL1wH/VwAmAvk4zZgXBDBgW1oi
J3ae86Ci4dGKF5c1jQ4T1gYPv34ZM/mM3rHzGFmXMZ/YJx5kUSqqAMPVTVw3Ha1ssnGJH0fKJ4vJ
EIhY4Nfm6K0aY7gkYMe63OiHoq+MS8V5gBHnE2VoronL8a47ycJ0ZsJbHnVprN4mrZf19tphLzmj
gGrwNZBBBuiVqqQT0hkf6W1Gykzi1KkD+IFIlTMt2w==
=ELbk
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6726-1
April 09, 2024

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4,
linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4,
linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4,
linux-raspi, linux-raspi-5.4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS (Available with Ubuntu Pro)

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-bluefield: Linux kernel for NVIDIA BlueField platforms
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gkeop: Linux kernel for Google Container Engine (GKE) systems
- linux-ibm: Linux kernel for IBM cloud systems
- linux-kvm: Linux kernel for cloud environments
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-raspi: Linux kernel for Raspberry Pi systems
- linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems
- linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems
- linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe-5.4: Linux hardware enablement (HWE) kernel
- linux-ibm-5.4: Linux kernel for IBM cloud systems
- linux-oracle-5.4: Linux kernel for Oracle Cloud systems
- linux-raspi-5.4: Linux kernel for Raspberry Pi systems

Details:

Pratyush Yadav discovered that the Xen network backend implementation in
the Linux kernel did not properly handle zero length data request, leading
to a null pointer dereference vulnerability. An attacker in a guest VM
could possibly use this to cause a denial of service (host domain crash).
(CVE-2023-46838)

It was discovered that the IPv6 implementation of the Linux kernel did not
properly manage route cache memory usage. A remote attacker could use this
to cause a denial of service (memory exhaustion). (CVE-2023-52340)

It was discovered that the device mapper driver in the Linux kernel did not
properly validate target size during certain memory allocations. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2023-52429, CVE-2024-23851)

Dan Carpenter discovered that the netfilter subsystem in the Linux kernel
did not store data in properly sized memory locations. A local user could
use this to cause a denial of service (system crash). (CVE-2024-0607)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Architecture specifics;
- Cryptographic API;
- Android drivers;
- EDAC drivers;
- GPU drivers;
- Media drivers;
- MTD block device drivers;
- Network drivers;
- NVME drivers;
- TTY drivers;
- Userspace I/O drivers;
- F2FS file system;
- GFS2 file system;
- IPv6 Networking;
- AppArmor security module;
(CVE-2023-52464, CVE-2023-52448, CVE-2023-52457, CVE-2023-52443,
CVE-2023-52439, CVE-2023-52612, CVE-2024-26633, CVE-2024-26597,
CVE-2023-52449, CVE-2023-52444, CVE-2023-52609, CVE-2023-52469,
CVE-2023-52445, CVE-2023-52451, CVE-2023-52470, CVE-2023-52454,
CVE-2023-52436, CVE-2023-52438)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
linux-image-5.4.0-1069-ibm 5.4.0-1069.74
linux-image-5.4.0-1082-bluefield 5.4.0-1082.89
linux-image-5.4.0-1089-gkeop 5.4.0-1089.93
linux-image-5.4.0-1106-raspi 5.4.0-1106.118
linux-image-5.4.0-1110-kvm 5.4.0-1110.117
linux-image-5.4.0-1121-oracle 5.4.0-1121.130
linux-image-5.4.0-1122-aws 5.4.0-1122.132
linux-image-5.4.0-1126-gcp 5.4.0-1126.135
linux-image-5.4.0-1127-azure 5.4.0-1127.134
linux-image-5.4.0-176-generic 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae 5.4.0-176.196
linux-image-5.4.0-176-lowlatency 5.4.0-176.196
linux-image-aws-lts-20.04 5.4.0.1122.119
linux-image-azure-lts-20.04 5.4.0.1127.121
linux-image-bluefield 5.4.0.1082.78
linux-image-gcp-lts-20.04 5.4.0.1126.128
linux-image-generic 5.4.0.176.174
linux-image-generic-lpae 5.4.0.176.174
linux-image-gkeop 5.4.0.1089.87
linux-image-gkeop-5.4 5.4.0.1089.87
linux-image-ibm-lts-20.04 5.4.0.1069.98
linux-image-kvm 5.4.0.1110.106
linux-image-lowlatency 5.4.0.176.174
linux-image-oem 5.4.0.176.174
linux-image-oem-osp1 5.4.0.176.174
linux-image-oracle-lts-20.04 5.4.0.1121.114
linux-image-raspi 5.4.0.1106.136
linux-image-raspi2 5.4.0.1106.136
linux-image-virtual 5.4.0.176.174

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
linux-image-5.4.0-1069-ibm 5.4.0-1069.74~18.04.1
linux-image-5.4.0-1106-raspi 5.4.0-1106.118~18.04.1
linux-image-5.4.0-1121-oracle 5.4.0-1121.130~18.04.1
linux-image-5.4.0-1122-aws 5.4.0-1122.132~18.04.1
linux-image-5.4.0-1126-gcp 5.4.0-1126.135~18.04.1
linux-image-5.4.0-1127-azure 5.4.0-1127.134~18.04.1
linux-image-5.4.0-175-generic 5.4.0-175.195~18.04.1
linux-image-5.4.0-175-lowlatency 5.4.0-175.195~18.04.1
linux-image-aws 5.4.0.1122.132~18.04.1
linux-image-azure 5.4.0.1127.134~18.04.1
linux-image-gcp 5.4.0.1126.135~18.04.1
linux-image-generic-hwe-18.04 5.4.0.175.195~18.04.1
linux-image-ibm 5.4.0.1069.79
linux-image-lowlatency-hwe-18.04 5.4.0.175.195~18.04.1
linux-image-oem 5.4.0.175.195~18.04.1
linux-image-oem-osp1 5.4.0.175.195~18.04.1
linux-image-oracle 5.4.0.1121.130~18.04.1
linux-image-raspi-hwe-18.04 5.4.0.1106.103
linux-image-snapdragon-hwe-18.04 5.4.0.175.195~18.04.1
linux-image-virtual-hwe-18.04 5.4.0.175.195~18.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6726-1
CVE-2023-46838, CVE-2023-52340, CVE-2023-52429, CVE-2023-52436,
CVE-2023-52438, CVE-2023-52439, CVE-2023-52443, CVE-2023-52444,
CVE-2023-52445, CVE-2023-52448, CVE-2023-52449, CVE-2023-52451,
CVE-2023-52454, CVE-2023-52457, CVE-2023-52464, CVE-2023-52469,
CVE-2023-52470, CVE-2023-52609, CVE-2023-52612, CVE-2024-0607,
CVE-2024-23851, CVE-2024-26597, CVE-2024-26633

Package Information:
https://launchpad.net/ubuntu/+source/linux/5.4.0-176.196
https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1122.132
https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1127.134
https://launchpad.net/ubuntu/+source/linux-bluefield/5.4.0-1082.89
https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1126.135
https://launchpad.net/ubuntu/+source/linux-gkeop/5.4.0-1089.93
https://launchpad.net/ubuntu/+source/linux-ibm/5.4.0-1069.74
https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1110.117
https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1121.130
https://launchpad.net/ubuntu/+source/linux-raspi/5.4.0-1106.118

[USN-6724-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmYVTIcFAwAAAAAACgkQZ0GeRcM5nt0V
3wgAmwto1Dfm5wwHwZN2CMGSfZAeF8gtimXwX2MI6fI68x6Ftf6Rs0xdmQIrXK9RQKmyyDtuEgVy
6/Z/IFab91ftCFo0vVZLRj6VPDgWym68HttCfHDly4OzzvnrJqncxe2sTRVwqSpyNRWiyYa9ZfWV
TKnvPyJRECyaqw6taDZwZ3SWTxlBTob0GAJCStwcQskEOPaSFvnxvrblaB+HAH9nXoHkJNzf/Agx
jx1wT0nBHJjQx1iZ1eRKQeDJSWo8oa4x/QJmaBjub8NclWYeXPOqRob+TUjVPqtmyr9iaK+aEOet
aJuB9/Uqi8xOpxyhkLEICXGy6GG/D1OtLpgjWbICPA==
=XAy4
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6724-1
April 09, 2024

linux, linux-aws, linux-azure, linux-azure-6.5, linux-gcp, linux-gcp-6.5,
linux-hwe-6.5, linux-laptop, linux-lowlatency, linux-lowlatency-hwe-6.5,
linux-oem-6.5, linux-oracle, linux-oracle-6.5, linux-starfive,
linux-starfive-6.5 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.10
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-laptop: Linux kernel for Lenovo X13s ARM laptops
- linux-lowlatency: Linux low latency kernel
- linux-oracle: Linux kernel for Oracle Cloud systems
- linux-starfive: Linux kernel for StarFive processors
- linux-azure-6.5: Linux kernel for Microsoft Azure cloud systems
- linux-gcp-6.5: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe-6.5: Linux hardware enablement (HWE) kernel
- linux-lowlatency-hwe-6.5: Linux low latency kernel
- linux-oem-6.5: Linux kernel for OEM systems
- linux-oracle-6.5: Linux kernel for Oracle Cloud systems
- linux-starfive-6.5: Linux kernel for StarFive processors

Details:

Pratyush Yadav discovered that the Xen network backend implementation in
the Linux kernel did not properly handle zero length data request, leading
to a null pointer dereference vulnerability. An attacker in a guest VM
could possibly use this to cause a denial of service (host domain crash).
(CVE-2023-46838)

It was discovered that the Habana's AI Processors driver in the Linux
kernel did not properly initialize certain data structures before passing
them to user space. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2023-50431)

It was discovered that the device mapper driver in the Linux kernel did not
properly validate target size during certain memory allocations. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2023-52429, CVE-2024-23851)

It was discovered that the CIFS network file system implementation in the
Linux kernel did not properly validate certain SMB messages, leading to an
out-of-bounds read vulnerability. An attacker could use this to cause a
denial of service (system crash) or possibly expose sensitive information.
(CVE-2023-6610)

Yang Chaoming discovered that the KSMBD implementation in the Linux kernel
did not properly validate request buffer sizes, leading to an out-of-bounds
read vulnerability. An attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information. (CVE-2024-22705)

Chenyuan Yang discovered that the btrfs file system in the Linux kernel did
not properly handle read operations on newly created subvolumes in certain
conditions. A local attacker could use this to cause a denial of service
(system crash). (CVE-2024-23850)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Android drivers;
- Userspace I/O drivers;
- F2FS file system;
- SMB network file system;
- Networking core;
(CVE-2023-52434, CVE-2023-52436, CVE-2023-52435, CVE-2023-52439,
CVE-2023-52438)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
linux-image-6.5.0-1011-starfive 6.5.0-1011.12
linux-image-6.5.0-1013-laptop 6.5.0-1013.16
linux-image-6.5.0-1017-aws 6.5.0-1017.17
linux-image-6.5.0-1017-gcp 6.5.0-1017.17
linux-image-6.5.0-1018-azure 6.5.0-1018.19
linux-image-6.5.0-1018-azure-fde 6.5.0-1018.19
linux-image-6.5.0-1020-oracle 6.5.0-1020.20
linux-image-6.5.0-1020-oracle-64k 6.5.0-1020.20
linux-image-6.5.0-27-generic 6.5.0-27.28
linux-image-6.5.0-27-generic-64k 6.5.0-27.28
linux-image-6.5.0-27-lowlatency 6.5.0-27.28.1
linux-image-6.5.0-27-lowlatency-64k 6.5.0-27.28.1
linux-image-aws 6.5.0.1017.17
linux-image-azure 6.5.0.1018.22
linux-image-azure-fde 6.5.0.1018.22
linux-image-gcp 6.5.0.1017.17
linux-image-generic 6.5.0.27.27
linux-image-generic-64k 6.5.0.27.27
linux-image-generic-lpae 6.5.0.27.27
linux-image-kvm 6.5.0.27.27
linux-image-laptop-23.10 6.5.0.1013.16
linux-image-lowlatency 6.5.0.27.28.18
linux-image-lowlatency-64k 6.5.0.27.28.18
linux-image-oracle 6.5.0.1020.22
linux-image-oracle-64k 6.5.0.1020.22
linux-image-starfive 6.5.0.1011.13
linux-image-virtual 6.5.0.27.27

Ubuntu 22.04 LTS:
linux-image-6.5.0-1011-starfive 6.5.0-1011.12~22.04.1
linux-image-6.5.0-1017-gcp 6.5.0-1017.17~22.04.1
linux-image-6.5.0-1018-azure 6.5.0-1018.19~22.04.2
linux-image-6.5.0-1018-azure-fde 6.5.0-1018.19~22.04.2
linux-image-6.5.0-1019-oem 6.5.0-1019.20
linux-image-6.5.0-1020-oracle 6.5.0-1020.20~22.04.1
linux-image-6.5.0-1020-oracle-64k 6.5.0-1020.20~22.04.1
linux-image-6.5.0-27-generic 6.5.0-27.28~22.04.1
linux-image-6.5.0-27-generic-64k 6.5.0-27.28~22.04.1
linux-image-6.5.0-27-lowlatency 6.5.0-27.28.1~22.04.1
linux-image-6.5.0-27-lowlatency-64k 6.5.0-27.28.1~22.04.1
linux-image-azure 6.5.0.1018.19~22.04.2
linux-image-azure-fde 6.5.0.1018.19~22.04.2
linux-image-gcp 6.5.0.1017.17~22.04.1
linux-image-generic-64k-hwe-22.04 6.5.0.27.28~22.04.1
linux-image-generic-hwe-22.04 6.5.0.27.28~22.04.1
linux-image-lowlatency-64k-hwe-22.04 6.5.0.27.28.1~22.04.1
linux-image-lowlatency-hwe-22.04 6.5.0.27.28.1~22.04.1
linux-image-oem-22.04 6.5.0.1019.21
linux-image-oem-22.04a 6.5.0.1019.21
linux-image-oem-22.04b 6.5.0.1019.21
linux-image-oem-22.04c 6.5.0.1019.21
linux-image-oem-22.04d 6.5.0.1019.21
linux-image-oracle 6.5.0.1020.20~22.04.1
linux-image-oracle-64k 6.5.0.1020.20~22.04.1
linux-image-starfive 6.5.0.1011.12~22.04.1
linux-image-virtual-hwe-22.04 6.5.0.27.28~22.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-6724-1
CVE-2023-46838, CVE-2023-50431, CVE-2023-52429, CVE-2023-52434,
CVE-2023-52435, CVE-2023-52436, CVE-2023-52438, CVE-2023-52439,
CVE-2023-6610, CVE-2024-22705, CVE-2024-23850, CVE-2024-23851

Package Information:
https://launchpad.net/ubuntu/+source/linux/6.5.0-27.28
https://launchpad.net/ubuntu/+source/linux-aws/6.5.0-1017.17
https://launchpad.net/ubuntu/+source/linux-azure/6.5.0-1018.19
https://launchpad.net/ubuntu/+source/linux-gcp/6.5.0-1017.17
https://launchpad.net/ubuntu/+source/linux-laptop/6.5.0-1013.16
https://launchpad.net/ubuntu/+source/linux-lowlatency/6.5.0-27.28.1
https://launchpad.net/ubuntu/+source/linux-oracle/6.5.0-1020.20
https://launchpad.net/ubuntu/+source/linux-starfive/6.5.0-1011.12
https://launchpad.net/ubuntu/+source/linux-azure-6.5/6.5.0-1018.19~22.04.2
https://launchpad.net/ubuntu/+source/linux-gcp-6.5/6.5.0-1017.17~22.04.1
https://launchpad.net/ubuntu/+source/linux-hwe-6.5/6.5.0-27.28~22.04.1

https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-6.5/6.5.0-27.28.1~22.04.1
https://launchpad.net/ubuntu/+source/linux-oem-6.5/6.5.0-1019.20
https://launchpad.net/ubuntu/+source/linux-oracle-6.5/6.5.0-1020.20~22.04.1

https://launchpad.net/ubuntu/+source/linux-starfive-6.5/6.5.0-1011.12~22.04.1

[USN-6723-1] Bind vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEhC9y9XdAFQPCvYXchGmXSGiknnUFAmYVQfMFAwAAAAAACgkQhGmXSGiknnXl
TQ/8DfJcbLG1WGcgBEmke65+INPRatOd8wUQ7tMs1LvIH85S/tFw4Nxh3OlpGrbqD7qjoUrTl8DI
PIjmBvmJH7qjbkXQI7oYVCnCA0RrlDPLUQMAxUWbxpADrRZ55geDFC+k1fjAqCSxm9jL3MFcJqDE
4YjXOG2cZ7aY6r2TSjbuE51bbe54zql33+85gReLiTN1+1NO6zw7+UNvK3YUortIVLMl5JkEpyrF
L6hGDFFFapE+JfhoDBatQOTASWLDe1rb8WW7+1Mtw2mSJ4my8X6dUekDeArcUa78SQyDtuQ94ibZ
7hqgA44rgJ24PDxjGGM6CAKy8vjZINGkkSIcUSLf8xYFcrahOVmhOnEiEP9tE8+S/L0OV1tTXxqm
xDOJCm3F9gzx7CqgnisqOTEcWa2b5gitLZc4cuc6SfBfStV+fK3CQ11XnSBWx/GnAAATGSbvOdND
qJsi4HZs/uaC9L7GfaAcJ+w3liIzJ/nQp5qOdFC4VkqCWousoNN79931nnnSBs+qMTsACTFFZB9b
XScGNNQrX4wb+iLW9UlOvMAsdGAyF0RcwJAwi4BO1TKFKCjREsocFpnvI3UwAJEkOng1qT9sBkmO
aWjq9Kt/jQLbT0VionzS8vd6BSHPsSwR0Rt9FkEXKOz3vpXPmrrnCq1UF10IkMOAfaLMJy7gNTNr
fIU=
=FQQm
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6723-1
April 09, 2024

bind9 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS (Available with Ubuntu Pro)
- Ubuntu 16.04 LTS (Available with Ubuntu Pro)
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)

Summary:

Bind could be made to crash if it received specially crafted
input.

Software Description:
- bind9: Internet Domain Name Server

Details:

Elias Heftrig, Haya Schulmann, Niklas Vogel, and Michael Waidner discovered
that Bind icorrectly handled validating DNSSEC messages. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2023-50387)

It was discovered that Bind incorrectly handled preparing an NSEC3 closest
encloser proof. A remote attacker could possibly use this issue to cause
Bind to consume resources, leading to a denial of service. (CVE-2023-50868)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
bind9 1:9.11.3+dfsg-1ubuntu1.19+esm3

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
bind9 1:9.10.3.dfsg.P4-8ubuntu1.19+esm8

Ubuntu 14.04 LTS (Available with Ubuntu Pro):
bind9 1:9.9.5.dfsg-3ubuntu0.19+esm12

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6723-1
CVE-2023-50387, CVE-2023-50868