Tonight's meeting is REMOTE ONLY.
Jim Brown will be speaking about "QEMU on BSDs".
Streaming will be from:
https://www.nycbug.org/index?action=streaming
Be sure to join IRC on #nycbug on Libera.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
https://lists.nycbug.org:8443/mailman/listinfo/announce
Wednesday, November 6, 2024
[USN-7088-3] Linux kernel vulnerabilities
==========================================================================
Ubuntu Security Notice USN-7088-3
November 06, 2024
linux-aws-5.4, linux-oracle-5.4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems
- linux-oracle-5.4: Linux kernel for Oracle Cloud systems
Details:
Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the
Linux kernel contained an integer overflow vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2022-36402)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- PowerPC architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Android drivers;
- Serial ATA and Parallel ATA drivers;
- ATM drivers;
- Drivers core;
- CPU frequency scaling framework;
- Device frequency scaling framework;
- GPU drivers;
- HID subsystem;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Input Device core drivers;
- Input Device (Miscellaneous) drivers;
- IOMMU subsystem;
- IRQ chip drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- EEPROM drivers;
- VMware VMCI Driver;
- MMC subsystem;
- Network drivers;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- Device tree and open firmware driver;
- Parport drivers;
- PCI subsystem;
- Pin controllers subsystem;
- Remote Processor subsystem;
- S/390 drivers;
- SCSI drivers;
- QCOM SoC drivers;
- Direct Digital Synthesis drivers;
- TTY drivers;
- Userspace I/O drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- BTRFS file system;
- File systems infrastructure;
- Ext4 file system;
- F2FS file system;
- JFS file system;
- NILFS2 file system;
- BPF subsystem;
- Core kernel;
- DMA mapping infrastructure;
- Tracing infrastructure;
- Radix Tree data structure library;
- Kernel userspace event delivery library;
- Objagg library;
- Memory management;
- Amateur Radio drivers;
- Bluetooth subsystem;
- CAN network layer;
- Networking core;
- Ethtool driver;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- KCM (Kernel Connection Multiplexor) sockets driver;
- MAC80211 subsystem;
- Netfilter;
- Network traffic control;
- SCTP protocol;
- Sun RPC protocol;
- TIPC protocol;
- TLS protocol;
- Wireless networking;
- AppArmor security module;
- Simplified Mandatory Access Control Kernel framework;
- SoC audio core drivers;
- USB sound devices;
(CVE-2021-47212, CVE-2024-44965, CVE-2024-46676, CVE-2024-41091,
CVE-2024-44946, CVE-2024-43894, CVE-2024-26668, CVE-2024-42259,
CVE-2024-42295, CVE-2024-46685, CVE-2024-46722, CVE-2024-45028,
CVE-2024-46815, CVE-2024-41081, CVE-2024-41022, CVE-2024-44948,
CVE-2024-42301, CVE-2024-43914, CVE-2024-46771, CVE-2024-42289,
CVE-2024-43841, CVE-2024-41042, CVE-2024-44999, CVE-2024-43893,
CVE-2024-46758, CVE-2024-46828, CVE-2024-36484, CVE-2024-26669,
CVE-2024-44952, CVE-2024-42265, CVE-2024-42311, CVE-2024-43880,
CVE-2024-41070, CVE-2024-46829, CVE-2024-42292, CVE-2024-46719,
CVE-2024-41020, CVE-2024-41015, CVE-2024-42283, CVE-2024-46744,
CVE-2024-46679, CVE-2024-46800, CVE-2024-46777, CVE-2024-43835,
CVE-2024-42271, CVE-2024-43882, CVE-2024-41072, CVE-2024-35848,
CVE-2024-43860, CVE-2024-38611, CVE-2024-26607, CVE-2024-47663,
CVE-2024-46780, CVE-2024-46675, CVE-2024-45003, CVE-2024-44969,
CVE-2024-42244, CVE-2024-43856, CVE-2024-46755, CVE-2024-42286,
CVE-2024-41063, CVE-2024-41068, CVE-2024-46743, CVE-2024-43839,
CVE-2024-41065, CVE-2023-52531, CVE-2024-41090, CVE-2024-46747,
CVE-2023-52614, CVE-2024-43853, CVE-2024-46737, CVE-2024-45021,
CVE-2024-41012, CVE-2024-41064, CVE-2024-26800, CVE-2024-42246,
CVE-2024-43908, CVE-2024-46723, CVE-2024-42310, CVE-2024-46781,
CVE-2023-52918, CVE-2024-42313, CVE-2024-45006, CVE-2024-43890,
CVE-2024-44954, CVE-2024-43858, CVE-2024-41098, CVE-2024-41071,
CVE-2024-26641, CVE-2024-42280, CVE-2024-46673, CVE-2024-43846,
CVE-2024-46721, CVE-2024-47667, CVE-2024-26885, CVE-2024-42304,
CVE-2024-46745, CVE-2024-26640, CVE-2024-43861, CVE-2024-42287,
CVE-2024-44998, CVE-2024-40929, CVE-2024-41073, CVE-2024-46689,
CVE-2024-44944, CVE-2024-46756, CVE-2024-42305, CVE-2024-42284,
CVE-2024-42281, CVE-2024-42288, CVE-2024-41011, CVE-2024-47668,
CVE-2024-43830, CVE-2024-46740, CVE-2024-46677, CVE-2024-43867,
CVE-2024-46783, CVE-2024-46844, CVE-2024-43854, CVE-2024-42297,
CVE-2024-46738, CVE-2024-46739, CVE-2024-44947, CVE-2024-43883,
CVE-2024-43884, CVE-2024-46798, CVE-2024-46757, CVE-2024-43879,
CVE-2024-47659, CVE-2024-46817, CVE-2024-45008, CVE-2024-47669,
CVE-2024-43871, CVE-2024-44960, CVE-2024-27051, CVE-2024-44988,
CVE-2024-46840, CVE-2024-41059, CVE-2024-46822, CVE-2024-42276,
CVE-2024-45026, CVE-2024-46761, CVE-2024-44995, CVE-2024-44987,
CVE-2024-26891, CVE-2024-46782, CVE-2024-42309, CVE-2024-42131,
CVE-2024-46759, CVE-2024-42229, CVE-2024-46714, CVE-2024-42290,
CVE-2024-44935, CVE-2024-42285, CVE-2024-38602, CVE-2024-43829,
CVE-2024-42306, CVE-2024-41017, CVE-2024-45025, CVE-2024-46818,
CVE-2024-46750)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
linux-image-5.4.0-1134-oracle 5.4.0-1134.143~18.04.1
Available with Ubuntu Pro
linux-image-5.4.0-1135-aws 5.4.0-1135.145~18.04.1
Available with Ubuntu Pro
linux-image-aws 5.4.0.1135.145~18.04.1
Available with Ubuntu Pro
linux-image-oracle 5.4.0.1134.143~18.04.1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7088-3
https://ubuntu.com/security/notices/USN-7088-2
https://ubuntu.com/security/notices/USN-7088-1
CVE-2021-47212, CVE-2022-36402, CVE-2023-52531, CVE-2023-52614,
CVE-2023-52918, CVE-2024-26607, CVE-2024-26640, CVE-2024-26641,
CVE-2024-26668, CVE-2024-26669, CVE-2024-26800, CVE-2024-26885,
CVE-2024-26891, CVE-2024-27051, CVE-2024-35848, CVE-2024-36484,
CVE-2024-38602, CVE-2024-38611, CVE-2024-40929, CVE-2024-41011,
CVE-2024-41012, CVE-2024-41015, CVE-2024-41017, CVE-2024-41020,
CVE-2024-41022, CVE-2024-41042, CVE-2024-41059, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41068, CVE-2024-41070,
CVE-2024-41071, CVE-2024-41072, CVE-2024-41073, CVE-2024-41081,
CVE-2024-41090, CVE-2024-41091, CVE-2024-41098, CVE-2024-42131,
CVE-2024-42229, CVE-2024-42244, CVE-2024-42246, CVE-2024-42259,
CVE-2024-42265, CVE-2024-42271, CVE-2024-42276, CVE-2024-42280,
CVE-2024-42281, CVE-2024-42283, CVE-2024-42284, CVE-2024-42285,
CVE-2024-42286, CVE-2024-42287, CVE-2024-42288, CVE-2024-42289,
CVE-2024-42290, CVE-2024-42292, CVE-2024-42295, CVE-2024-42297,
CVE-2024-42301, CVE-2024-42304, CVE-2024-42305, CVE-2024-42306,
CVE-2024-42309, CVE-2024-42310, CVE-2024-42311, CVE-2024-42313,
CVE-2024-43829, CVE-2024-43830, CVE-2024-43835, CVE-2024-43839,
CVE-2024-43841, CVE-2024-43846, CVE-2024-43853, CVE-2024-43854,
CVE-2024-43856, CVE-2024-43858, CVE-2024-43860, CVE-2024-43861,
CVE-2024-43867, CVE-2024-43871, CVE-2024-43879, CVE-2024-43880,
CVE-2024-43882, CVE-2024-43883, CVE-2024-43884, CVE-2024-43890,
CVE-2024-43893, CVE-2024-43894, CVE-2024-43908, CVE-2024-43914,
CVE-2024-44935, CVE-2024-44944, CVE-2024-44946, CVE-2024-44947,
CVE-2024-44948, CVE-2024-44952, CVE-2024-44954, CVE-2024-44960,
CVE-2024-44965, CVE-2024-44969, CVE-2024-44987, CVE-2024-44988,
CVE-2024-44995, CVE-2024-44998, CVE-2024-44999, CVE-2024-45003,
CVE-2024-45006, CVE-2024-45008, CVE-2024-45021, CVE-2024-45025,
CVE-2024-45026, CVE-2024-45028, CVE-2024-46673, CVE-2024-46675,
CVE-2024-46676, CVE-2024-46677, CVE-2024-46679, CVE-2024-46685,
CVE-2024-46689, CVE-2024-46714, CVE-2024-46719, CVE-2024-46721,
CVE-2024-46722, CVE-2024-46723, CVE-2024-46737, CVE-2024-46738,
CVE-2024-46739, CVE-2024-46740, CVE-2024-46743, CVE-2024-46744,
CVE-2024-46745, CVE-2024-46747, CVE-2024-46750, CVE-2024-46755,
CVE-2024-46756, CVE-2024-46757, CVE-2024-46758, CVE-2024-46759,
CVE-2024-46761, CVE-2024-46771, CVE-2024-46777, CVE-2024-46780,
CVE-2024-46781, CVE-2024-46782, CVE-2024-46783, CVE-2024-46798,
CVE-2024-46800, CVE-2024-46815, CVE-2024-46817, CVE-2024-46818,
CVE-2024-46822, CVE-2024-46828, CVE-2024-46829, CVE-2024-46840,
CVE-2024-46844, CVE-2024-47659, CVE-2024-47663, CVE-2024-47667,
CVE-2024-47668, CVE-2024-47669
Ubuntu Security Notice USN-7088-3
November 06, 2024
linux-aws-5.4, linux-oracle-5.4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems
- linux-oracle-5.4: Linux kernel for Oracle Cloud systems
Details:
Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the
Linux kernel contained an integer overflow vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2022-36402)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- PowerPC architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Android drivers;
- Serial ATA and Parallel ATA drivers;
- ATM drivers;
- Drivers core;
- CPU frequency scaling framework;
- Device frequency scaling framework;
- GPU drivers;
- HID subsystem;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Input Device core drivers;
- Input Device (Miscellaneous) drivers;
- IOMMU subsystem;
- IRQ chip drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- EEPROM drivers;
- VMware VMCI Driver;
- MMC subsystem;
- Network drivers;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- Device tree and open firmware driver;
- Parport drivers;
- PCI subsystem;
- Pin controllers subsystem;
- Remote Processor subsystem;
- S/390 drivers;
- SCSI drivers;
- QCOM SoC drivers;
- Direct Digital Synthesis drivers;
- TTY drivers;
- Userspace I/O drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- BTRFS file system;
- File systems infrastructure;
- Ext4 file system;
- F2FS file system;
- JFS file system;
- NILFS2 file system;
- BPF subsystem;
- Core kernel;
- DMA mapping infrastructure;
- Tracing infrastructure;
- Radix Tree data structure library;
- Kernel userspace event delivery library;
- Objagg library;
- Memory management;
- Amateur Radio drivers;
- Bluetooth subsystem;
- CAN network layer;
- Networking core;
- Ethtool driver;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- KCM (Kernel Connection Multiplexor) sockets driver;
- MAC80211 subsystem;
- Netfilter;
- Network traffic control;
- SCTP protocol;
- Sun RPC protocol;
- TIPC protocol;
- TLS protocol;
- Wireless networking;
- AppArmor security module;
- Simplified Mandatory Access Control Kernel framework;
- SoC audio core drivers;
- USB sound devices;
(CVE-2021-47212, CVE-2024-44965, CVE-2024-46676, CVE-2024-41091,
CVE-2024-44946, CVE-2024-43894, CVE-2024-26668, CVE-2024-42259,
CVE-2024-42295, CVE-2024-46685, CVE-2024-46722, CVE-2024-45028,
CVE-2024-46815, CVE-2024-41081, CVE-2024-41022, CVE-2024-44948,
CVE-2024-42301, CVE-2024-43914, CVE-2024-46771, CVE-2024-42289,
CVE-2024-43841, CVE-2024-41042, CVE-2024-44999, CVE-2024-43893,
CVE-2024-46758, CVE-2024-46828, CVE-2024-36484, CVE-2024-26669,
CVE-2024-44952, CVE-2024-42265, CVE-2024-42311, CVE-2024-43880,
CVE-2024-41070, CVE-2024-46829, CVE-2024-42292, CVE-2024-46719,
CVE-2024-41020, CVE-2024-41015, CVE-2024-42283, CVE-2024-46744,
CVE-2024-46679, CVE-2024-46800, CVE-2024-46777, CVE-2024-43835,
CVE-2024-42271, CVE-2024-43882, CVE-2024-41072, CVE-2024-35848,
CVE-2024-43860, CVE-2024-38611, CVE-2024-26607, CVE-2024-47663,
CVE-2024-46780, CVE-2024-46675, CVE-2024-45003, CVE-2024-44969,
CVE-2024-42244, CVE-2024-43856, CVE-2024-46755, CVE-2024-42286,
CVE-2024-41063, CVE-2024-41068, CVE-2024-46743, CVE-2024-43839,
CVE-2024-41065, CVE-2023-52531, CVE-2024-41090, CVE-2024-46747,
CVE-2023-52614, CVE-2024-43853, CVE-2024-46737, CVE-2024-45021,
CVE-2024-41012, CVE-2024-41064, CVE-2024-26800, CVE-2024-42246,
CVE-2024-43908, CVE-2024-46723, CVE-2024-42310, CVE-2024-46781,
CVE-2023-52918, CVE-2024-42313, CVE-2024-45006, CVE-2024-43890,
CVE-2024-44954, CVE-2024-43858, CVE-2024-41098, CVE-2024-41071,
CVE-2024-26641, CVE-2024-42280, CVE-2024-46673, CVE-2024-43846,
CVE-2024-46721, CVE-2024-47667, CVE-2024-26885, CVE-2024-42304,
CVE-2024-46745, CVE-2024-26640, CVE-2024-43861, CVE-2024-42287,
CVE-2024-44998, CVE-2024-40929, CVE-2024-41073, CVE-2024-46689,
CVE-2024-44944, CVE-2024-46756, CVE-2024-42305, CVE-2024-42284,
CVE-2024-42281, CVE-2024-42288, CVE-2024-41011, CVE-2024-47668,
CVE-2024-43830, CVE-2024-46740, CVE-2024-46677, CVE-2024-43867,
CVE-2024-46783, CVE-2024-46844, CVE-2024-43854, CVE-2024-42297,
CVE-2024-46738, CVE-2024-46739, CVE-2024-44947, CVE-2024-43883,
CVE-2024-43884, CVE-2024-46798, CVE-2024-46757, CVE-2024-43879,
CVE-2024-47659, CVE-2024-46817, CVE-2024-45008, CVE-2024-47669,
CVE-2024-43871, CVE-2024-44960, CVE-2024-27051, CVE-2024-44988,
CVE-2024-46840, CVE-2024-41059, CVE-2024-46822, CVE-2024-42276,
CVE-2024-45026, CVE-2024-46761, CVE-2024-44995, CVE-2024-44987,
CVE-2024-26891, CVE-2024-46782, CVE-2024-42309, CVE-2024-42131,
CVE-2024-46759, CVE-2024-42229, CVE-2024-46714, CVE-2024-42290,
CVE-2024-44935, CVE-2024-42285, CVE-2024-38602, CVE-2024-43829,
CVE-2024-42306, CVE-2024-41017, CVE-2024-45025, CVE-2024-46818,
CVE-2024-46750)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
linux-image-5.4.0-1134-oracle 5.4.0-1134.143~18.04.1
Available with Ubuntu Pro
linux-image-5.4.0-1135-aws 5.4.0-1135.145~18.04.1
Available with Ubuntu Pro
linux-image-aws 5.4.0.1135.145~18.04.1
Available with Ubuntu Pro
linux-image-oracle 5.4.0.1134.143~18.04.1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7088-3
https://ubuntu.com/security/notices/USN-7088-2
https://ubuntu.com/security/notices/USN-7088-1
CVE-2021-47212, CVE-2022-36402, CVE-2023-52531, CVE-2023-52614,
CVE-2023-52918, CVE-2024-26607, CVE-2024-26640, CVE-2024-26641,
CVE-2024-26668, CVE-2024-26669, CVE-2024-26800, CVE-2024-26885,
CVE-2024-26891, CVE-2024-27051, CVE-2024-35848, CVE-2024-36484,
CVE-2024-38602, CVE-2024-38611, CVE-2024-40929, CVE-2024-41011,
CVE-2024-41012, CVE-2024-41015, CVE-2024-41017, CVE-2024-41020,
CVE-2024-41022, CVE-2024-41042, CVE-2024-41059, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41068, CVE-2024-41070,
CVE-2024-41071, CVE-2024-41072, CVE-2024-41073, CVE-2024-41081,
CVE-2024-41090, CVE-2024-41091, CVE-2024-41098, CVE-2024-42131,
CVE-2024-42229, CVE-2024-42244, CVE-2024-42246, CVE-2024-42259,
CVE-2024-42265, CVE-2024-42271, CVE-2024-42276, CVE-2024-42280,
CVE-2024-42281, CVE-2024-42283, CVE-2024-42284, CVE-2024-42285,
CVE-2024-42286, CVE-2024-42287, CVE-2024-42288, CVE-2024-42289,
CVE-2024-42290, CVE-2024-42292, CVE-2024-42295, CVE-2024-42297,
CVE-2024-42301, CVE-2024-42304, CVE-2024-42305, CVE-2024-42306,
CVE-2024-42309, CVE-2024-42310, CVE-2024-42311, CVE-2024-42313,
CVE-2024-43829, CVE-2024-43830, CVE-2024-43835, CVE-2024-43839,
CVE-2024-43841, CVE-2024-43846, CVE-2024-43853, CVE-2024-43854,
CVE-2024-43856, CVE-2024-43858, CVE-2024-43860, CVE-2024-43861,
CVE-2024-43867, CVE-2024-43871, CVE-2024-43879, CVE-2024-43880,
CVE-2024-43882, CVE-2024-43883, CVE-2024-43884, CVE-2024-43890,
CVE-2024-43893, CVE-2024-43894, CVE-2024-43908, CVE-2024-43914,
CVE-2024-44935, CVE-2024-44944, CVE-2024-44946, CVE-2024-44947,
CVE-2024-44948, CVE-2024-44952, CVE-2024-44954, CVE-2024-44960,
CVE-2024-44965, CVE-2024-44969, CVE-2024-44987, CVE-2024-44988,
CVE-2024-44995, CVE-2024-44998, CVE-2024-44999, CVE-2024-45003,
CVE-2024-45006, CVE-2024-45008, CVE-2024-45021, CVE-2024-45025,
CVE-2024-45026, CVE-2024-45028, CVE-2024-46673, CVE-2024-46675,
CVE-2024-46676, CVE-2024-46677, CVE-2024-46679, CVE-2024-46685,
CVE-2024-46689, CVE-2024-46714, CVE-2024-46719, CVE-2024-46721,
CVE-2024-46722, CVE-2024-46723, CVE-2024-46737, CVE-2024-46738,
CVE-2024-46739, CVE-2024-46740, CVE-2024-46743, CVE-2024-46744,
CVE-2024-46745, CVE-2024-46747, CVE-2024-46750, CVE-2024-46755,
CVE-2024-46756, CVE-2024-46757, CVE-2024-46758, CVE-2024-46759,
CVE-2024-46761, CVE-2024-46771, CVE-2024-46777, CVE-2024-46780,
CVE-2024-46781, CVE-2024-46782, CVE-2024-46783, CVE-2024-46798,
CVE-2024-46800, CVE-2024-46815, CVE-2024-46817, CVE-2024-46818,
CVE-2024-46822, CVE-2024-46828, CVE-2024-46829, CVE-2024-46840,
CVE-2024-46844, CVE-2024-47659, CVE-2024-47663, CVE-2024-47667,
CVE-2024-47668, CVE-2024-47669
Tuesday, November 5, 2024
[USN-7093-1] Werkzeug vulnerability
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmcqolsACgkQZWnYVadE
vpMsIw//f2vrXQbNg4dkmihl/6aBRrIBGmyJb1adtVgQUvu5e+OyzUU2D7GsD4JC
ZNQZwBbAiJzTh7WfTaghCgbEcfrIcGYV1adkiLYxt35/xO93xutVv0vE/MULDR4Q
izjSnSxuFcOiCclLkkAAL05orc4DlGaVOFSqSKo7Sd/YacddYG48w86cMPesXr0y
dLEIdnZJGqunCg+UE2q8fW9yxejfpEryJVbetOQKQC6kWa94/VwY3chq+VBn6ZKA
JnxL3YHnp8hE8dPK9Y9xWoEthscr68tpU20paSTqyQnGFWlplgtb00SGKIWhoPoa
OEGTdI9ke8brs20eexxk/xhDQ77tSw8Ma2ISnYEbWaCAu755LRbCbfI8etBdgsir
EQ4y/H1ffF3BGQ9HN8ckbbpUgq7HNFmNTU06QfZ4kMzy+BgYOWCpUWqx7Gwz0auc
GUApMZ/ooleOz1vZD+p5IzBfOwjJOELtqvx1xYuHhj5D1vtfTyq+tjqLsQ5EAI0m
k/Goanrc/KY1TVCeSBm5o3ZBnmEOQPewrU8OazavUkPxvFDo4FVYFSrIINaSgpBd
anDBHs00FKtuDkW3FQ639rcUOMsyZkwxGl/XUZW4IPSbSQJqjEgdRY2WMlZak26s
LcQILpwQoKpOMIS5IecYIOKhW3jmPCS5b75nIxfdDQwfKRLStEk=
=1DDu
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7093-1
November 05, 2024
python-werkzeug vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Werkzeug could be made to consume resources if it received specially
crafted network traffic.
Software Description:
- python-werkzeug: collection of utilities for WSGI applications
Details:
It was discovered that Werkzeug incorrectly handled multiple form
submission requests. A remote attacker could possibly use this issue to
cause Werkzeug to consume resources, leading to a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
python3-werkzeug 3.0.3-1ubuntu0.1
Ubuntu 24.04 LTS
python3-werkzeug 3.0.1-3ubuntu0.2
Ubuntu 22.04 LTS
python3-werkzeug 2.0.2+dfsg1-1ubuntu0.22.04.3
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7093-1
CVE-2024-49767
Package Information:
https://launchpad.net/ubuntu/+source/python-werkzeug/3.0.3-1ubuntu0.1
https://launchpad.net/ubuntu/+source/python-werkzeug/3.0.1-3ubuntu0.2
https://launchpad.net/ubuntu/+source/python-werkzeug/2.0.2+dfsg1-1ubuntu0.22.04.3
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmcqolsACgkQZWnYVadE
vpMsIw//f2vrXQbNg4dkmihl/6aBRrIBGmyJb1adtVgQUvu5e+OyzUU2D7GsD4JC
ZNQZwBbAiJzTh7WfTaghCgbEcfrIcGYV1adkiLYxt35/xO93xutVv0vE/MULDR4Q
izjSnSxuFcOiCclLkkAAL05orc4DlGaVOFSqSKo7Sd/YacddYG48w86cMPesXr0y
dLEIdnZJGqunCg+UE2q8fW9yxejfpEryJVbetOQKQC6kWa94/VwY3chq+VBn6ZKA
JnxL3YHnp8hE8dPK9Y9xWoEthscr68tpU20paSTqyQnGFWlplgtb00SGKIWhoPoa
OEGTdI9ke8brs20eexxk/xhDQ77tSw8Ma2ISnYEbWaCAu755LRbCbfI8etBdgsir
EQ4y/H1ffF3BGQ9HN8ckbbpUgq7HNFmNTU06QfZ4kMzy+BgYOWCpUWqx7Gwz0auc
GUApMZ/ooleOz1vZD+p5IzBfOwjJOELtqvx1xYuHhj5D1vtfTyq+tjqLsQ5EAI0m
k/Goanrc/KY1TVCeSBm5o3ZBnmEOQPewrU8OazavUkPxvFDo4FVYFSrIINaSgpBd
anDBHs00FKtuDkW3FQ639rcUOMsyZkwxGl/XUZW4IPSbSQJqjEgdRY2WMlZak26s
LcQILpwQoKpOMIS5IecYIOKhW3jmPCS5b75nIxfdDQwfKRLStEk=
=1DDu
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7093-1
November 05, 2024
python-werkzeug vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Werkzeug could be made to consume resources if it received specially
crafted network traffic.
Software Description:
- python-werkzeug: collection of utilities for WSGI applications
Details:
It was discovered that Werkzeug incorrectly handled multiple form
submission requests. A remote attacker could possibly use this issue to
cause Werkzeug to consume resources, leading to a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
python3-werkzeug 3.0.3-1ubuntu0.1
Ubuntu 24.04 LTS
python3-werkzeug 3.0.1-3ubuntu0.2
Ubuntu 22.04 LTS
python3-werkzeug 2.0.2+dfsg1-1ubuntu0.22.04.3
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7093-1
CVE-2024-49767
Package Information:
https://launchpad.net/ubuntu/+source/python-werkzeug/3.0.3-1ubuntu0.1
https://launchpad.net/ubuntu/+source/python-werkzeug/3.0.1-3ubuntu0.2
https://launchpad.net/ubuntu/+source/python-werkzeug/2.0.2+dfsg1-1ubuntu0.22.04.3
Inactive packagers removal for the F41 release cycle
As final step of the Inactive Packagers Policy [1] for the F41 release
cycle, I've ran the script to identify the final list of packagers that
were inactive. Below are the results with the list of affected users for
which I will shortly open a ticket to Fedora Infra for removal from
packagers group:
### These 65 users didn't reply and are going to be removed from
packagers: ###
- ahalaney
- andrewponomarenko
- anthr76
- anushkasrinivasa
- aravuri
- arcress
- asaleh
- beau-gosse-dev
- beuc
- bnemec
- caolanm
- chandankumar
- cjatherton
- codeblock
- costello
- csnyder
- csoriano
- dbenoit
- derekh
- dghubble
- dhodovsk
- drsmith2
- dvossel
- efi
- egustavs
- fabiand
- garnacho
- greenscientist
- heathhey
- jhernand
- jhrozek
- jlayton
- jzerdik
- kathenas
- lczerner
- lucasagomes
- marcvs
- mauelsha
- mavjs
- mgrabovs
- mjg59
- mprahl
- mzidek
- nhosoi
- nickfarrell
- npocs
- pkotvan
- pravins
- psavelye
- rhea
- rkanagar
- rskvaril
- sbueno
- scox
- slinabery
- spontsle
- spredzy
- swhiteho
- tbielawa
- tekkamanninja
- tomegun
- tomspur
- trodgers
- vladius
- ykaliuta
### These users agreed to be removed from packagers: ###
- athmane
- jvcelak
- linuxsystemroles
- mharmsen
- tingping
- vkmc
Between the start and the final step of the procedure, some users that
were at first identified as inactive have resumed some sort of activity
(but they didn't actively replied to the policy ticket) and they were
identified by the script, so they will NOT be removed from packagers:
### These 8 users resumed activity: ###
- iarnell
- leamas
- lennart
- mcurlej
- mikeb
- mmaslano
- pfrields
- turboturtle
[1]
https://docs.fedoraproject.org/en-US/fesco/Policy_for_inactive_packagers/
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
cycle, I've ran the script to identify the final list of packagers that
were inactive. Below are the results with the list of affected users for
which I will shortly open a ticket to Fedora Infra for removal from
packagers group:
### These 65 users didn't reply and are going to be removed from
packagers: ###
- ahalaney
- andrewponomarenko
- anthr76
- anushkasrinivasa
- aravuri
- arcress
- asaleh
- beau-gosse-dev
- beuc
- bnemec
- caolanm
- chandankumar
- cjatherton
- codeblock
- costello
- csnyder
- csoriano
- dbenoit
- derekh
- dghubble
- dhodovsk
- drsmith2
- dvossel
- efi
- egustavs
- fabiand
- garnacho
- greenscientist
- heathhey
- jhernand
- jhrozek
- jlayton
- jzerdik
- kathenas
- lczerner
- lucasagomes
- marcvs
- mauelsha
- mavjs
- mgrabovs
- mjg59
- mprahl
- mzidek
- nhosoi
- nickfarrell
- npocs
- pkotvan
- pravins
- psavelye
- rhea
- rkanagar
- rskvaril
- sbueno
- scox
- slinabery
- spontsle
- spredzy
- swhiteho
- tbielawa
- tekkamanninja
- tomegun
- tomspur
- trodgers
- vladius
- ykaliuta
### These users agreed to be removed from packagers: ###
- athmane
- jvcelak
- linuxsystemroles
- mharmsen
- tingping
- vkmc
Between the start and the final step of the procedure, some users that
were at first identified as inactive have resumed some sort of activity
(but they didn't actively replied to the policy ticket) and they were
identified by the script, so they will NOT be removed from packagers:
### These 8 users resumed activity: ###
- iarnell
- leamas
- lennart
- mcurlej
- mikeb
- mmaslano
- pfrields
- turboturtle
[1]
https://docs.fedoraproject.org/en-US/fesco/Policy_for_inactive_packagers/
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
[USN-7092-1] mpg123 vulnerability
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmcqNjcACgkQZWnYVadE
vpOiVA/5Aee4n4sE9YvPjerPtChXg6lkIgUgBjhKHT3/uWx1dI+sQ/SKOutN2ASG
GUbtlIsebiW9/mFxq+nuakWtF2Qa8IuTK3HXrgWiKaNCFcVEU0BljkL6an4FKs9B
g87u5Od5f6sMCYAne9/gXDbWZkHP8O+M87/EwG2DAXxFaTufkJKwn/rF3uhO9LM2
551Fzol2wWF2O6Kds6NFQPsEXuXCU4DlASXIebIuZrIpSShLYX/PyNAfmGwZzSiV
etZnSLms1vyMM35dJtIdKh+j8UOB3Q/qMF+jRdEx8HR2yoe1FMALM8l04wDYVpNT
DNYh7SNA3+vTUhzzuKiNqzVK5RNUfvbQT6UY+OHjCz01RBn+TFY/XszIBzA2mmz8
6ggW8JmqVlVdJUsQ3xkGILotu64wNuPY4wzTpRU9SiBBRJOG2LPUCRfiAaVJbeYD
OZc23/AbqRKMlazhoew64RhwePsQgVrqVsk9Gvd6J6wtyFhjkMTplTlQPScBsPjo
+vX2o4bVA8AAb+J/XvG5p62I3koDIRrKIQOns6EF32B2mSAIa+3KXpNor5iE5bIp
RCnrYQ6g5agP4MAl4O2170YnNKzyGp3147jcB3VR7vTLJgBDBDZIfP2EySNtrr7A
x+DV5Ds8Vga4wk/R/6QaE6LhrULYa0ddUMEPh1l9mcknIOPYdNE=
=fZox
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7092-1
November 05, 2024
mpg123 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
mpg123 could be made to crash or run programs as your login if it opened a
specially crafted file.
Software Description:
- mpg123: MPEG layer 1/2/3 audio player
Details:
It was discovered that mpg123 incorrectly handled certain mp3 files. If a
user or automated system were tricked into opening a specially crafted mp3
file, a remote attacker could use this issue to cause mpg123 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libmpg123-0t64 1.32.7-1ubuntu0.1
mpg123 1.32.7-1ubuntu0.1
Ubuntu 24.04 LTS
libmpg123-0t64 1.32.5-1ubuntu1.1
mpg123 1.32.5-1ubuntu1.1
Ubuntu 22.04 LTS
libmpg123-0 1.29.3-1ubuntu0.1
mpg123 1.29.3-1ubuntu0.1
Ubuntu 20.04 LTS
libmpg123-0 1.25.13-1ubuntu0.1
mpg123 1.25.13-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7092-1
CVE-2024-10573
Package Information:
https://launchpad.net/ubuntu/+source/mpg123/1.32.7-1ubuntu0.1
https://launchpad.net/ubuntu/+source/mpg123/1.32.5-1ubuntu1.1
https://launchpad.net/ubuntu/+source/mpg123/1.29.3-1ubuntu0.1
https://launchpad.net/ubuntu/+source/mpg123/1.25.13-1ubuntu0.1
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmcqNjcACgkQZWnYVadE
vpOiVA/5Aee4n4sE9YvPjerPtChXg6lkIgUgBjhKHT3/uWx1dI+sQ/SKOutN2ASG
GUbtlIsebiW9/mFxq+nuakWtF2Qa8IuTK3HXrgWiKaNCFcVEU0BljkL6an4FKs9B
g87u5Od5f6sMCYAne9/gXDbWZkHP8O+M87/EwG2DAXxFaTufkJKwn/rF3uhO9LM2
551Fzol2wWF2O6Kds6NFQPsEXuXCU4DlASXIebIuZrIpSShLYX/PyNAfmGwZzSiV
etZnSLms1vyMM35dJtIdKh+j8UOB3Q/qMF+jRdEx8HR2yoe1FMALM8l04wDYVpNT
DNYh7SNA3+vTUhzzuKiNqzVK5RNUfvbQT6UY+OHjCz01RBn+TFY/XszIBzA2mmz8
6ggW8JmqVlVdJUsQ3xkGILotu64wNuPY4wzTpRU9SiBBRJOG2LPUCRfiAaVJbeYD
OZc23/AbqRKMlazhoew64RhwePsQgVrqVsk9Gvd6J6wtyFhjkMTplTlQPScBsPjo
+vX2o4bVA8AAb+J/XvG5p62I3koDIRrKIQOns6EF32B2mSAIa+3KXpNor5iE5bIp
RCnrYQ6g5agP4MAl4O2170YnNKzyGp3147jcB3VR7vTLJgBDBDZIfP2EySNtrr7A
x+DV5Ds8Vga4wk/R/6QaE6LhrULYa0ddUMEPh1l9mcknIOPYdNE=
=fZox
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7092-1
November 05, 2024
mpg123 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
mpg123 could be made to crash or run programs as your login if it opened a
specially crafted file.
Software Description:
- mpg123: MPEG layer 1/2/3 audio player
Details:
It was discovered that mpg123 incorrectly handled certain mp3 files. If a
user or automated system were tricked into opening a specially crafted mp3
file, a remote attacker could use this issue to cause mpg123 to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libmpg123-0t64 1.32.7-1ubuntu0.1
mpg123 1.32.7-1ubuntu0.1
Ubuntu 24.04 LTS
libmpg123-0t64 1.32.5-1ubuntu1.1
mpg123 1.32.5-1ubuntu1.1
Ubuntu 22.04 LTS
libmpg123-0 1.29.3-1ubuntu0.1
mpg123 1.29.3-1ubuntu0.1
Ubuntu 20.04 LTS
libmpg123-0 1.25.13-1ubuntu0.1
mpg123 1.25.13-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7092-1
CVE-2024-10573
Package Information:
https://launchpad.net/ubuntu/+source/mpg123/1.32.7-1ubuntu0.1
https://launchpad.net/ubuntu/+source/mpg123/1.32.5-1ubuntu1.1
https://launchpad.net/ubuntu/+source/mpg123/1.29.3-1ubuntu0.1
https://launchpad.net/ubuntu/+source/mpg123/1.25.13-1ubuntu0.1
[USN-7091-1] Ruby vulnerabilities
==========================================================================
Ubuntu Security Notice USN-7091-1
November 05, 2024
ruby3.0, ruby3.2, ruby3.3 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Ruby.
Software Description:
- ruby3.3: Object-oriented scripting language
- ruby3.2: Object-oriented scripting language
- ruby3.0: Object-oriented scripting language
Details:
It was discovered that Ruby incorrectly handled parsing of an XML document
that has specific XML characters in an attribute value using REXML gem. An
attacker could use this issue to cause Ruby to crash, resulting in a denial
of service. This issue only affected in Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2024-35176, CVE-2024-39908, CVE-2024-41123)
It was discovered that Ruby incorrectly handled parsing of an XML document
that has many entity expansions with SAX2 or pull parser API. An attacker
could use this issue to cause Ruby to crash, resulting in a denial of
service. (CVE-2024-41946)
It was discovered that Ruby incorrectly handled parsing of an XML document
that has many digits in a hex numeric character reference. An attacker
could use this issue to cause Ruby to crash, resulting in a denial of
service. (CVE-2024-49761)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libruby3.3 3.3.4-2ubuntu5.1
ruby3.3 3.3.4-2ubuntu5.1
Ubuntu 24.04 LTS
libruby3.2 3.2.3-1ubuntu0.24.04.3
ruby3.2 3.2.3-1ubuntu0.24.04.3
Ubuntu 22.04 LTS
libruby3.0 3.0.2-7ubuntu2.8
ruby3.0 3.0.2-7ubuntu2.8
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7091-1
CVE-2024-35176, CVE-2024-39908, CVE-2024-41123, CVE-2024-41946,
CVE-2024-49761
Package Information:
https://launchpad.net/ubuntu/+source/ruby3.3/3.3.4-2ubuntu5.1
https://launchpad.net/ubuntu/+source/ruby3.2/3.2.3-1ubuntu0.24.04.3
https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubuntu2.8
Ubuntu Security Notice USN-7091-1
November 05, 2024
ruby3.0, ruby3.2, ruby3.3 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Ruby.
Software Description:
- ruby3.3: Object-oriented scripting language
- ruby3.2: Object-oriented scripting language
- ruby3.0: Object-oriented scripting language
Details:
It was discovered that Ruby incorrectly handled parsing of an XML document
that has specific XML characters in an attribute value using REXML gem. An
attacker could use this issue to cause Ruby to crash, resulting in a denial
of service. This issue only affected in Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2024-35176, CVE-2024-39908, CVE-2024-41123)
It was discovered that Ruby incorrectly handled parsing of an XML document
that has many entity expansions with SAX2 or pull parser API. An attacker
could use this issue to cause Ruby to crash, resulting in a denial of
service. (CVE-2024-41946)
It was discovered that Ruby incorrectly handled parsing of an XML document
that has many digits in a hex numeric character reference. An attacker
could use this issue to cause Ruby to crash, resulting in a denial of
service. (CVE-2024-49761)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libruby3.3 3.3.4-2ubuntu5.1
ruby3.3 3.3.4-2ubuntu5.1
Ubuntu 24.04 LTS
libruby3.2 3.2.3-1ubuntu0.24.04.3
ruby3.2 3.2.3-1ubuntu0.24.04.3
Ubuntu 22.04 LTS
libruby3.0 3.0.2-7ubuntu2.8
ruby3.0 3.0.2-7ubuntu2.8
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7091-1
CVE-2024-35176, CVE-2024-39908, CVE-2024-41123, CVE-2024-41946,
CVE-2024-49761
Package Information:
https://launchpad.net/ubuntu/+source/ruby3.3/3.3.4-2ubuntu5.1
https://launchpad.net/ubuntu/+source/ruby3.2/3.2.3-1ubuntu0.24.04.3
https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubuntu2.8
Monday, November 4, 2024
[USN-7083-1] OpenJPEG vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmcpeocFAwAAAAAACgkQuGrtzot7pOeD
Ogv/XS4ZmFdLjP7xAtd+o5mmc4NivaYrVleqMKbj73NL8wu2ZXCieNd/GGAN73zjZmCUzhDt8PMX
3RD/MVs8Qlv4EQ34jUwtD17HWRoIethcycf/2qEXQ9CoAcxcn4mvhOKA3WJuUp9+IsLZB51zPUus
xz3gGW/Kb/C63FthinsycGR+VOLqGQVfelhPYl32olUfN3lLhZ2qwtl6OmHiolQecOeWOb0APRcp
k4t4fyIQaCOX3H2hDGAMql2EMQrQmfuFjD2pGDrvhR6WMCta9WSKvd0HsHMJiRF62RLcfiPAuV9p
HQVfayuP2ZbgoTzoBWpWHS/lbuC6/K1l8seTsKumNTWgmCOkMEUZuJFGh44Uw8XwUHKQFl60AmqN
940OZx1JKpJDUhB0p9L/jo5NpQRmO2TeJmgFLWOG7sh+cg5ldbIUOmkwDH6Oy2i0vXqspnCMmMkI
o0U88Uv36bWmaF68EUKWlJIPo1UIOKigOqSmA43pbInfWOPAGr+mGASbXCDW
=qa/C
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7083-1
November 05, 2024
openjpeg2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in OpenJPEG.
Software Description:
- openjpeg2: JPEG 2000 image compression/decompression library
Details:
It was discovered that OpenJPEG incorrectly handled certain memory
operations when using the command line "-ImgDir" in a directory with a
large number of files, leading to an integer overflow vulnerability. An
attacker could potentially use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2021-29338)
It was discovered that OpenJPEG incorrectly handled decompressing certain
.j2k files in sycc420_to_rgb, leading to a heap-based buffer overflow
vulnerability. If a user or automated system were tricked into opening
a specially crafted file, an attacker could possibly use this issue to
execute arbitrary code. (CVE-2021-3575)
It was discovered that OpenJPEG incorrectly handled certain memory
operations in the opj2_decompress program. An attacker could potentially
use this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-1122)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libopenjp2-7 2.5.0-2ubuntu1.1
libopenjpip7 2.5.0-2ubuntu1.1
Ubuntu 24.04 LTS
libopenjp2-7 2.5.0-2ubuntu0.2
libopenjpip7 2.5.0-2ubuntu0.2
Ubuntu 22.04 LTS
libopenjp2-7 2.4.0-6ubuntu0.2
libopenjp3d7 2.4.0-6ubuntu0.2
libopenjpip7 2.4.0-6ubuntu0.2
Ubuntu 20.04 LTS
libopenjp2-7 2.3.1-1ubuntu4.20.04.3
libopenjp3d7 2.3.1-1ubuntu4.20.04.3
libopenjpip7 2.3.1-1ubuntu4.20.04.3
Ubuntu 18.04 LTS
libopenjp2-7 2.3.0-2+deb10u2ubuntu0.1~esm3
Available with Ubuntu Pro
libopenjp3d7 2.3.0-2+deb10u2ubuntu0.1~esm3
Available with Ubuntu Pro
libopenjpip7 2.3.0-2+deb10u2ubuntu0.1~esm3
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libopenjp2-7 2.1.2-1.1+deb9u6ubuntu0.1~esm6
Available with Ubuntu Pro
libopenjp3d7 2.1.2-1.1+deb9u6ubuntu0.1~esm6
Available with Ubuntu Pro
libopenjpip7 2.1.2-1.1+deb9u6ubuntu0.1~esm6
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7083-1
CVE-2021-29338, CVE-2021-3575, CVE-2022-1122
Package Information:
https://launchpad.net/ubuntu/+source/openjpeg2/2.5.0-2ubuntu1.1
https://launchpad.net/ubuntu/+source/openjpeg2/2.5.0-2ubuntu0.2
https://launchpad.net/ubuntu/+source/openjpeg2/2.4.0-6ubuntu0.2
https://launchpad.net/ubuntu/+source/openjpeg2/2.3.1-1ubuntu4.20.04.3
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmcpeocFAwAAAAAACgkQuGrtzot7pOeD
Ogv/XS4ZmFdLjP7xAtd+o5mmc4NivaYrVleqMKbj73NL8wu2ZXCieNd/GGAN73zjZmCUzhDt8PMX
3RD/MVs8Qlv4EQ34jUwtD17HWRoIethcycf/2qEXQ9CoAcxcn4mvhOKA3WJuUp9+IsLZB51zPUus
xz3gGW/Kb/C63FthinsycGR+VOLqGQVfelhPYl32olUfN3lLhZ2qwtl6OmHiolQecOeWOb0APRcp
k4t4fyIQaCOX3H2hDGAMql2EMQrQmfuFjD2pGDrvhR6WMCta9WSKvd0HsHMJiRF62RLcfiPAuV9p
HQVfayuP2ZbgoTzoBWpWHS/lbuC6/K1l8seTsKumNTWgmCOkMEUZuJFGh44Uw8XwUHKQFl60AmqN
940OZx1JKpJDUhB0p9L/jo5NpQRmO2TeJmgFLWOG7sh+cg5ldbIUOmkwDH6Oy2i0vXqspnCMmMkI
o0U88Uv36bWmaF68EUKWlJIPo1UIOKigOqSmA43pbInfWOPAGr+mGASbXCDW
=qa/C
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7083-1
November 05, 2024
openjpeg2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in OpenJPEG.
Software Description:
- openjpeg2: JPEG 2000 image compression/decompression library
Details:
It was discovered that OpenJPEG incorrectly handled certain memory
operations when using the command line "-ImgDir" in a directory with a
large number of files, leading to an integer overflow vulnerability. An
attacker could potentially use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2021-29338)
It was discovered that OpenJPEG incorrectly handled decompressing certain
.j2k files in sycc420_to_rgb, leading to a heap-based buffer overflow
vulnerability. If a user or automated system were tricked into opening
a specially crafted file, an attacker could possibly use this issue to
execute arbitrary code. (CVE-2021-3575)
It was discovered that OpenJPEG incorrectly handled certain memory
operations in the opj2_decompress program. An attacker could potentially
use this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-1122)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libopenjp2-7 2.5.0-2ubuntu1.1
libopenjpip7 2.5.0-2ubuntu1.1
Ubuntu 24.04 LTS
libopenjp2-7 2.5.0-2ubuntu0.2
libopenjpip7 2.5.0-2ubuntu0.2
Ubuntu 22.04 LTS
libopenjp2-7 2.4.0-6ubuntu0.2
libopenjp3d7 2.4.0-6ubuntu0.2
libopenjpip7 2.4.0-6ubuntu0.2
Ubuntu 20.04 LTS
libopenjp2-7 2.3.1-1ubuntu4.20.04.3
libopenjp3d7 2.3.1-1ubuntu4.20.04.3
libopenjpip7 2.3.1-1ubuntu4.20.04.3
Ubuntu 18.04 LTS
libopenjp2-7 2.3.0-2+deb10u2ubuntu0.1~esm3
Available with Ubuntu Pro
libopenjp3d7 2.3.0-2+deb10u2ubuntu0.1~esm3
Available with Ubuntu Pro
libopenjpip7 2.3.0-2+deb10u2ubuntu0.1~esm3
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libopenjp2-7 2.1.2-1.1+deb9u6ubuntu0.1~esm6
Available with Ubuntu Pro
libopenjp3d7 2.1.2-1.1+deb9u6ubuntu0.1~esm6
Available with Ubuntu Pro
libopenjpip7 2.1.2-1.1+deb9u6ubuntu0.1~esm6
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7083-1
CVE-2021-29338, CVE-2021-3575, CVE-2022-1122
Package Information:
https://launchpad.net/ubuntu/+source/openjpeg2/2.5.0-2ubuntu1.1
https://launchpad.net/ubuntu/+source/openjpeg2/2.5.0-2ubuntu0.2
https://launchpad.net/ubuntu/+source/openjpeg2/2.4.0-6ubuntu0.2
https://launchpad.net/ubuntu/+source/openjpeg2/2.3.1-1ubuntu4.20.04.3
[USN-7089-2] Linux kernel vulnerabilities
==========================================================================
Ubuntu Security Notice USN-7089-2
November 04, 2024
linux-azure, linux-gcp, linux-ibm vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-ibm: Linux kernel for IBM cloud systems
Details:
Chenyuan Yang discovered that the USB Gadget subsystem in the Linux
kernel did not properly check for the device to be enabled before
writing. A local attacker could possibly use this to cause a denial of
service. (CVE-2024-25741)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- MIPS architecture;
- PA-RISC architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- x86 architecture;
- Cryptographic API;
- Serial ATA and Parallel ATA drivers;
- Null block device driver;
- Bluetooth drivers;
- Cdrom driver;
- Clock framework and drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Cirrus firmware drivers;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- Fastrpc Driver;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- NVMEM (Non Volatile Memory) drivers;
- PCI subsystem;
- Pin controllers subsystem;
- x86 platform drivers;
- S/390 drivers;
- SCSI drivers;
- Thermal drivers;
- TTY drivers;
- UFS subsystem;
- USB DSL drivers;
- USB core drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- VFIO drivers;
- VHOST drivers;
- File systems infrastructure;
- BTRFS file system;
- GFS2 file system;
- JFFS2 file system;
- JFS file system;
- Network file systems library;
- Network file system client;
- NILFS2 file system;
- NTFS3 file system;
- SMB network file system;
- Memory management;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- BPF subsystem;
- Core kernel;
- Bluetooth subsystem;
- CAN network layer;
- Ceph Core library;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- MAC80211 subsystem;
- Network traffic control;
- Sun RPC protocol;
- Wireless networking;
- AMD SoC Alsa drivers;
- SoC Audio for Freescale CPUs drivers;
- MediaTek ASoC drivers;
- SoC audio core drivers;
- SOF drivers;
- Sound sequencer drivers;
(CVE-2024-42104, CVE-2024-42101, CVE-2024-41052, CVE-2024-42157,
CVE-2024-41020, CVE-2024-41055, CVE-2024-42124, CVE-2023-52888,
CVE-2024-42079, CVE-2024-43858, CVE-2024-41075, CVE-2024-42073,
CVE-2024-42113, CVE-2024-42110, CVE-2024-41080, CVE-2024-42097,
CVE-2024-41046, CVE-2024-42076, CVE-2024-41010, CVE-2024-41018,
CVE-2024-42115, CVE-2024-41048, CVE-2024-42231, CVE-2024-42241,
CVE-2024-41034, CVE-2024-42065, CVE-2024-42140, CVE-2024-42094,
CVE-2024-41029, CVE-2024-42225, CVE-2024-41096, CVE-2024-42088,
CVE-2024-41087, CVE-2023-52887, CVE-2024-42141, CVE-2024-42135,
CVE-2024-42247, CVE-2024-39487, CVE-2024-42229, CVE-2024-42147,
CVE-2024-42252, CVE-2024-41038, CVE-2024-41083, CVE-2024-42091,
CVE-2024-42156, CVE-2024-42149, CVE-2024-41015, CVE-2024-41047,
CVE-2024-42129, CVE-2024-42120, CVE-2024-41097, CVE-2024-42243,
CVE-2024-42084, CVE-2024-42250, CVE-2024-41023, CVE-2024-41028,
CVE-2024-42108, CVE-2024-41045, CVE-2024-42098, CVE-2024-41064,
CVE-2024-42087, CVE-2024-42080, CVE-2024-41049, CVE-2024-42271,
CVE-2024-41037, CVE-2024-42114, CVE-2024-41044, CVE-2024-42126,
CVE-2024-42119, CVE-2024-42223, CVE-2024-42280, CVE-2024-42112,
CVE-2024-41019, CVE-2024-42133, CVE-2024-42152, CVE-2024-41074,
CVE-2024-41042, CVE-2024-41093, CVE-2024-41025, CVE-2024-42253,
CVE-2024-42136, CVE-2024-42127, CVE-2024-41036, CVE-2024-42237,
CVE-2024-42111, CVE-2024-41031, CVE-2024-41069, CVE-2024-41084,
CVE-2024-41076, CVE-2024-41090, CVE-2024-41088, CVE-2024-41070,
CVE-2024-42118, CVE-2024-42238, CVE-2024-42234, CVE-2024-41089,
CVE-2024-41095, CVE-2024-41085, CVE-2024-42106, CVE-2024-42155,
CVE-2024-42146, CVE-2024-42130, CVE-2024-42089, CVE-2024-42132,
CVE-2024-41091, CVE-2024-42153, CVE-2024-42236, CVE-2024-42085,
CVE-2024-41065, CVE-2024-41032, CVE-2024-42090, CVE-2024-41030,
CVE-2024-41017, CVE-2024-42230, CVE-2024-42144, CVE-2024-42137,
CVE-2024-41082, CVE-2024-41056, CVE-2024-42145, CVE-2024-41041,
CVE-2024-42240, CVE-2024-41081, CVE-2024-42103, CVE-2024-41053,
CVE-2024-42070, CVE-2024-42121, CVE-2024-42105, CVE-2024-41022,
CVE-2024-42151, CVE-2024-42142, CVE-2024-41035, CVE-2024-42232,
CVE-2024-41058, CVE-2024-42109, CVE-2024-41077, CVE-2024-42095,
CVE-2024-39486, CVE-2024-42131, CVE-2024-42068, CVE-2024-41073,
CVE-2024-41079, CVE-2024-42082, CVE-2024-41071, CVE-2024-41066,
CVE-2024-42102, CVE-2024-43855, CVE-2024-41061, CVE-2024-41072,
CVE-2024-41059, CVE-2024-41094, CVE-2024-41021, CVE-2024-41098,
CVE-2024-42158, CVE-2024-41033, CVE-2024-42096, CVE-2024-42251,
CVE-2024-42077, CVE-2024-42063, CVE-2024-42227, CVE-2024-41007,
CVE-2024-41057, CVE-2024-41063, CVE-2024-41039, CVE-2024-41067,
CVE-2024-41062, CVE-2024-42100, CVE-2024-42074, CVE-2024-42064,
CVE-2024-41092, CVE-2024-42128, CVE-2024-41086, CVE-2024-41054,
CVE-2024-42239, CVE-2024-41027, CVE-2024-42093, CVE-2024-42244,
CVE-2024-41050, CVE-2024-41012, CVE-2024-42246, CVE-2024-42117,
CVE-2024-42069, CVE-2024-42067, CVE-2024-42086, CVE-2024-42066,
CVE-2024-41060, CVE-2024-42248, CVE-2024-41068, CVE-2024-42161,
CVE-2024-42092, CVE-2024-42245, CVE-2024-41078, CVE-2024-42235,
CVE-2024-42150, CVE-2024-41051, CVE-2024-42138)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
linux-image-6.8.0-1014-ibm 6.8.0-1014.14
linux-image-6.8.0-1016-azure 6.8.0-1016.18
linux-image-6.8.0-1016-azure-fde 6.8.0-1016.18
linux-image-6.8.0-1016-gcp 6.8.0-1016.18
linux-image-azure 6.8.0-1016.18
linux-image-azure-fde 6.8.0-1016.18
linux-image-gcp 6.8.0-1016.18
linux-image-ibm 6.8.0-1014.14
linux-image-ibm-classic 6.8.0-1014.14
linux-image-ibm-lts-24.04 6.8.0-1014.14
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7089-2
https://ubuntu.com/security/notices/USN-7089-1
CVE-2023-52887, CVE-2023-52888, CVE-2024-25741, CVE-2024-39486,
CVE-2024-39487, CVE-2024-41007, CVE-2024-41010, CVE-2024-41012,
CVE-2024-41015, CVE-2024-41017, CVE-2024-41018, CVE-2024-41019,
CVE-2024-41020, CVE-2024-41021, CVE-2024-41022, CVE-2024-41023,
CVE-2024-41025, CVE-2024-41027, CVE-2024-41028, CVE-2024-41029,
CVE-2024-41030, CVE-2024-41031, CVE-2024-41032, CVE-2024-41033,
CVE-2024-41034, CVE-2024-41035, CVE-2024-41036, CVE-2024-41037,
CVE-2024-41038, CVE-2024-41039, CVE-2024-41041, CVE-2024-41042,
CVE-2024-41044, CVE-2024-41045, CVE-2024-41046, CVE-2024-41047,
CVE-2024-41048, CVE-2024-41049, CVE-2024-41050, CVE-2024-41051,
CVE-2024-41052, CVE-2024-41053, CVE-2024-41054, CVE-2024-41055,
CVE-2024-41056, CVE-2024-41057, CVE-2024-41058, CVE-2024-41059,
CVE-2024-41060, CVE-2024-41061, CVE-2024-41062, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41066, CVE-2024-41067,
CVE-2024-41068, CVE-2024-41069, CVE-2024-41070, CVE-2024-41071,
CVE-2024-41072, CVE-2024-41073, CVE-2024-41074, CVE-2024-41075,
CVE-2024-41076, CVE-2024-41077, CVE-2024-41078, CVE-2024-41079,
CVE-2024-41080, CVE-2024-41081, CVE-2024-41082, CVE-2024-41083,
CVE-2024-41084, CVE-2024-41085, CVE-2024-41086, CVE-2024-41087,
CVE-2024-41088, CVE-2024-41089, CVE-2024-41090, CVE-2024-41091,
CVE-2024-41092, CVE-2024-41093, CVE-2024-41094, CVE-2024-41095,
CVE-2024-41096, CVE-2024-41097, CVE-2024-41098, CVE-2024-42063,
CVE-2024-42064, CVE-2024-42065, CVE-2024-42066, CVE-2024-42067,
CVE-2024-42068, CVE-2024-42069, CVE-2024-42070, CVE-2024-42073,
CVE-2024-42074, CVE-2024-42076, CVE-2024-42077, CVE-2024-42079,
CVE-2024-42080, CVE-2024-42082, CVE-2024-42084, CVE-2024-42085,
CVE-2024-42086, CVE-2024-42087, CVE-2024-42088, CVE-2024-42089,
CVE-2024-42090, CVE-2024-42091, CVE-2024-42092, CVE-2024-42093,
CVE-2024-42094, CVE-2024-42095, CVE-2024-42096, CVE-2024-42097,
CVE-2024-42098, CVE-2024-42100, CVE-2024-42101, CVE-2024-42102,
CVE-2024-42103, CVE-2024-42104, CVE-2024-42105, CVE-2024-42106,
CVE-2024-42108, CVE-2024-42109, CVE-2024-42110, CVE-2024-42111,
CVE-2024-42112, CVE-2024-42113, CVE-2024-42114, CVE-2024-42115,
CVE-2024-42117, CVE-2024-42118, CVE-2024-42119, CVE-2024-42120,
CVE-2024-42121, CVE-2024-42124, CVE-2024-42126, CVE-2024-42127,
CVE-2024-42128, CVE-2024-42129, CVE-2024-42130, CVE-2024-42131,
CVE-2024-42132, CVE-2024-42133, CVE-2024-42135, CVE-2024-42136,
CVE-2024-42137, CVE-2024-42138, CVE-2024-42140, CVE-2024-42141,
CVE-2024-42142, CVE-2024-42144, CVE-2024-42145, CVE-2024-42146,
CVE-2024-42147, CVE-2024-42149, CVE-2024-42150, CVE-2024-42151,
CVE-2024-42152, CVE-2024-42153, CVE-2024-42155, CVE-2024-42156,
CVE-2024-42157, CVE-2024-42158, CVE-2024-42161, CVE-2024-42223,
CVE-2024-42225, CVE-2024-42227, CVE-2024-42229, CVE-2024-42230,
CVE-2024-42231, CVE-2024-42232, CVE-2024-42234, CVE-2024-42235,
CVE-2024-42236, CVE-2024-42237, CVE-2024-42238, CVE-2024-42239,
CVE-2024-42240, CVE-2024-42241, CVE-2024-42243, CVE-2024-42244,
CVE-2024-42245, CVE-2024-42246, CVE-2024-42247, CVE-2024-42248,
CVE-2024-42250, CVE-2024-42251, CVE-2024-42252, CVE-2024-42253,
CVE-2024-42271, CVE-2024-42280, CVE-2024-43855, CVE-2024-43858
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/6.8.0-1017.20
https://launchpad.net/ubuntu/+source/linux-gcp/6.8.0-1017.19
https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1015.15
Ubuntu Security Notice USN-7089-2
November 04, 2024
linux-azure, linux-gcp, linux-ibm vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-ibm: Linux kernel for IBM cloud systems
Details:
Chenyuan Yang discovered that the USB Gadget subsystem in the Linux
kernel did not properly check for the device to be enabled before
writing. A local attacker could possibly use this to cause a denial of
service. (CVE-2024-25741)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- MIPS architecture;
- PA-RISC architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- x86 architecture;
- Cryptographic API;
- Serial ATA and Parallel ATA drivers;
- Null block device driver;
- Bluetooth drivers;
- Cdrom driver;
- Clock framework and drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Cirrus firmware drivers;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- Fastrpc Driver;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- NVMEM (Non Volatile Memory) drivers;
- PCI subsystem;
- Pin controllers subsystem;
- x86 platform drivers;
- S/390 drivers;
- SCSI drivers;
- Thermal drivers;
- TTY drivers;
- UFS subsystem;
- USB DSL drivers;
- USB core drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- VFIO drivers;
- VHOST drivers;
- File systems infrastructure;
- BTRFS file system;
- GFS2 file system;
- JFFS2 file system;
- JFS file system;
- Network file systems library;
- Network file system client;
- NILFS2 file system;
- NTFS3 file system;
- SMB network file system;
- Memory management;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- BPF subsystem;
- Core kernel;
- Bluetooth subsystem;
- CAN network layer;
- Ceph Core library;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- MAC80211 subsystem;
- Network traffic control;
- Sun RPC protocol;
- Wireless networking;
- AMD SoC Alsa drivers;
- SoC Audio for Freescale CPUs drivers;
- MediaTek ASoC drivers;
- SoC audio core drivers;
- SOF drivers;
- Sound sequencer drivers;
(CVE-2024-42104, CVE-2024-42101, CVE-2024-41052, CVE-2024-42157,
CVE-2024-41020, CVE-2024-41055, CVE-2024-42124, CVE-2023-52888,
CVE-2024-42079, CVE-2024-43858, CVE-2024-41075, CVE-2024-42073,
CVE-2024-42113, CVE-2024-42110, CVE-2024-41080, CVE-2024-42097,
CVE-2024-41046, CVE-2024-42076, CVE-2024-41010, CVE-2024-41018,
CVE-2024-42115, CVE-2024-41048, CVE-2024-42231, CVE-2024-42241,
CVE-2024-41034, CVE-2024-42065, CVE-2024-42140, CVE-2024-42094,
CVE-2024-41029, CVE-2024-42225, CVE-2024-41096, CVE-2024-42088,
CVE-2024-41087, CVE-2023-52887, CVE-2024-42141, CVE-2024-42135,
CVE-2024-42247, CVE-2024-39487, CVE-2024-42229, CVE-2024-42147,
CVE-2024-42252, CVE-2024-41038, CVE-2024-41083, CVE-2024-42091,
CVE-2024-42156, CVE-2024-42149, CVE-2024-41015, CVE-2024-41047,
CVE-2024-42129, CVE-2024-42120, CVE-2024-41097, CVE-2024-42243,
CVE-2024-42084, CVE-2024-42250, CVE-2024-41023, CVE-2024-41028,
CVE-2024-42108, CVE-2024-41045, CVE-2024-42098, CVE-2024-41064,
CVE-2024-42087, CVE-2024-42080, CVE-2024-41049, CVE-2024-42271,
CVE-2024-41037, CVE-2024-42114, CVE-2024-41044, CVE-2024-42126,
CVE-2024-42119, CVE-2024-42223, CVE-2024-42280, CVE-2024-42112,
CVE-2024-41019, CVE-2024-42133, CVE-2024-42152, CVE-2024-41074,
CVE-2024-41042, CVE-2024-41093, CVE-2024-41025, CVE-2024-42253,
CVE-2024-42136, CVE-2024-42127, CVE-2024-41036, CVE-2024-42237,
CVE-2024-42111, CVE-2024-41031, CVE-2024-41069, CVE-2024-41084,
CVE-2024-41076, CVE-2024-41090, CVE-2024-41088, CVE-2024-41070,
CVE-2024-42118, CVE-2024-42238, CVE-2024-42234, CVE-2024-41089,
CVE-2024-41095, CVE-2024-41085, CVE-2024-42106, CVE-2024-42155,
CVE-2024-42146, CVE-2024-42130, CVE-2024-42089, CVE-2024-42132,
CVE-2024-41091, CVE-2024-42153, CVE-2024-42236, CVE-2024-42085,
CVE-2024-41065, CVE-2024-41032, CVE-2024-42090, CVE-2024-41030,
CVE-2024-41017, CVE-2024-42230, CVE-2024-42144, CVE-2024-42137,
CVE-2024-41082, CVE-2024-41056, CVE-2024-42145, CVE-2024-41041,
CVE-2024-42240, CVE-2024-41081, CVE-2024-42103, CVE-2024-41053,
CVE-2024-42070, CVE-2024-42121, CVE-2024-42105, CVE-2024-41022,
CVE-2024-42151, CVE-2024-42142, CVE-2024-41035, CVE-2024-42232,
CVE-2024-41058, CVE-2024-42109, CVE-2024-41077, CVE-2024-42095,
CVE-2024-39486, CVE-2024-42131, CVE-2024-42068, CVE-2024-41073,
CVE-2024-41079, CVE-2024-42082, CVE-2024-41071, CVE-2024-41066,
CVE-2024-42102, CVE-2024-43855, CVE-2024-41061, CVE-2024-41072,
CVE-2024-41059, CVE-2024-41094, CVE-2024-41021, CVE-2024-41098,
CVE-2024-42158, CVE-2024-41033, CVE-2024-42096, CVE-2024-42251,
CVE-2024-42077, CVE-2024-42063, CVE-2024-42227, CVE-2024-41007,
CVE-2024-41057, CVE-2024-41063, CVE-2024-41039, CVE-2024-41067,
CVE-2024-41062, CVE-2024-42100, CVE-2024-42074, CVE-2024-42064,
CVE-2024-41092, CVE-2024-42128, CVE-2024-41086, CVE-2024-41054,
CVE-2024-42239, CVE-2024-41027, CVE-2024-42093, CVE-2024-42244,
CVE-2024-41050, CVE-2024-41012, CVE-2024-42246, CVE-2024-42117,
CVE-2024-42069, CVE-2024-42067, CVE-2024-42086, CVE-2024-42066,
CVE-2024-41060, CVE-2024-42248, CVE-2024-41068, CVE-2024-42161,
CVE-2024-42092, CVE-2024-42245, CVE-2024-41078, CVE-2024-42235,
CVE-2024-42150, CVE-2024-41051, CVE-2024-42138)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
linux-image-6.8.0-1014-ibm 6.8.0-1014.14
linux-image-6.8.0-1016-azure 6.8.0-1016.18
linux-image-6.8.0-1016-azure-fde 6.8.0-1016.18
linux-image-6.8.0-1016-gcp 6.8.0-1016.18
linux-image-azure 6.8.0-1016.18
linux-image-azure-fde 6.8.0-1016.18
linux-image-gcp 6.8.0-1016.18
linux-image-ibm 6.8.0-1014.14
linux-image-ibm-classic 6.8.0-1014.14
linux-image-ibm-lts-24.04 6.8.0-1014.14
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7089-2
https://ubuntu.com/security/notices/USN-7089-1
CVE-2023-52887, CVE-2023-52888, CVE-2024-25741, CVE-2024-39486,
CVE-2024-39487, CVE-2024-41007, CVE-2024-41010, CVE-2024-41012,
CVE-2024-41015, CVE-2024-41017, CVE-2024-41018, CVE-2024-41019,
CVE-2024-41020, CVE-2024-41021, CVE-2024-41022, CVE-2024-41023,
CVE-2024-41025, CVE-2024-41027, CVE-2024-41028, CVE-2024-41029,
CVE-2024-41030, CVE-2024-41031, CVE-2024-41032, CVE-2024-41033,
CVE-2024-41034, CVE-2024-41035, CVE-2024-41036, CVE-2024-41037,
CVE-2024-41038, CVE-2024-41039, CVE-2024-41041, CVE-2024-41042,
CVE-2024-41044, CVE-2024-41045, CVE-2024-41046, CVE-2024-41047,
CVE-2024-41048, CVE-2024-41049, CVE-2024-41050, CVE-2024-41051,
CVE-2024-41052, CVE-2024-41053, CVE-2024-41054, CVE-2024-41055,
CVE-2024-41056, CVE-2024-41057, CVE-2024-41058, CVE-2024-41059,
CVE-2024-41060, CVE-2024-41061, CVE-2024-41062, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41066, CVE-2024-41067,
CVE-2024-41068, CVE-2024-41069, CVE-2024-41070, CVE-2024-41071,
CVE-2024-41072, CVE-2024-41073, CVE-2024-41074, CVE-2024-41075,
CVE-2024-41076, CVE-2024-41077, CVE-2024-41078, CVE-2024-41079,
CVE-2024-41080, CVE-2024-41081, CVE-2024-41082, CVE-2024-41083,
CVE-2024-41084, CVE-2024-41085, CVE-2024-41086, CVE-2024-41087,
CVE-2024-41088, CVE-2024-41089, CVE-2024-41090, CVE-2024-41091,
CVE-2024-41092, CVE-2024-41093, CVE-2024-41094, CVE-2024-41095,
CVE-2024-41096, CVE-2024-41097, CVE-2024-41098, CVE-2024-42063,
CVE-2024-42064, CVE-2024-42065, CVE-2024-42066, CVE-2024-42067,
CVE-2024-42068, CVE-2024-42069, CVE-2024-42070, CVE-2024-42073,
CVE-2024-42074, CVE-2024-42076, CVE-2024-42077, CVE-2024-42079,
CVE-2024-42080, CVE-2024-42082, CVE-2024-42084, CVE-2024-42085,
CVE-2024-42086, CVE-2024-42087, CVE-2024-42088, CVE-2024-42089,
CVE-2024-42090, CVE-2024-42091, CVE-2024-42092, CVE-2024-42093,
CVE-2024-42094, CVE-2024-42095, CVE-2024-42096, CVE-2024-42097,
CVE-2024-42098, CVE-2024-42100, CVE-2024-42101, CVE-2024-42102,
CVE-2024-42103, CVE-2024-42104, CVE-2024-42105, CVE-2024-42106,
CVE-2024-42108, CVE-2024-42109, CVE-2024-42110, CVE-2024-42111,
CVE-2024-42112, CVE-2024-42113, CVE-2024-42114, CVE-2024-42115,
CVE-2024-42117, CVE-2024-42118, CVE-2024-42119, CVE-2024-42120,
CVE-2024-42121, CVE-2024-42124, CVE-2024-42126, CVE-2024-42127,
CVE-2024-42128, CVE-2024-42129, CVE-2024-42130, CVE-2024-42131,
CVE-2024-42132, CVE-2024-42133, CVE-2024-42135, CVE-2024-42136,
CVE-2024-42137, CVE-2024-42138, CVE-2024-42140, CVE-2024-42141,
CVE-2024-42142, CVE-2024-42144, CVE-2024-42145, CVE-2024-42146,
CVE-2024-42147, CVE-2024-42149, CVE-2024-42150, CVE-2024-42151,
CVE-2024-42152, CVE-2024-42153, CVE-2024-42155, CVE-2024-42156,
CVE-2024-42157, CVE-2024-42158, CVE-2024-42161, CVE-2024-42223,
CVE-2024-42225, CVE-2024-42227, CVE-2024-42229, CVE-2024-42230,
CVE-2024-42231, CVE-2024-42232, CVE-2024-42234, CVE-2024-42235,
CVE-2024-42236, CVE-2024-42237, CVE-2024-42238, CVE-2024-42239,
CVE-2024-42240, CVE-2024-42241, CVE-2024-42243, CVE-2024-42244,
CVE-2024-42245, CVE-2024-42246, CVE-2024-42247, CVE-2024-42248,
CVE-2024-42250, CVE-2024-42251, CVE-2024-42252, CVE-2024-42253,
CVE-2024-42271, CVE-2024-42280, CVE-2024-43855, CVE-2024-43858
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/6.8.0-1017.20
https://launchpad.net/ubuntu/+source/linux-gcp/6.8.0-1017.19
https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1015.15
[USN-7088-2] Linux kernel vulnerabilities
==========================================================================
Ubuntu Security Notice USN-7088-2
November 04, 2024
linux-azure, linux-bluefield vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-bluefield: Linux kernel for NVIDIA BlueField platforms
Details:
Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the
Linux kernel contained an integer overflow vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2022-36402)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- PowerPC architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Android drivers;
- Serial ATA and Parallel ATA drivers;
- ATM drivers;
- Drivers core;
- CPU frequency scaling framework;
- Device frequency scaling framework;
- GPU drivers;
- HID subsystem;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Input Device core drivers;
- Input Device (Miscellaneous) drivers;
- IOMMU subsystem;
- IRQ chip drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- EEPROM drivers;
- VMware VMCI Driver;
- MMC subsystem;
- Network drivers;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- Device tree and open firmware driver;
- Parport drivers;
- PCI subsystem;
- Pin controllers subsystem;
- Remote Processor subsystem;
- S/390 drivers;
- SCSI drivers;
- QCOM SoC drivers;
- Direct Digital Synthesis drivers;
- TTY drivers;
- Userspace I/O drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- BTRFS file system;
- File systems infrastructure;
- Ext4 file system;
- F2FS file system;
- JFS file system;
- NILFS2 file system;
- BPF subsystem;
- Core kernel;
- DMA mapping infrastructure;
- Tracing infrastructure;
- Radix Tree data structure library;
- Kernel userspace event delivery library;
- Objagg library;
- Memory management;
- Amateur Radio drivers;
- Bluetooth subsystem;
- CAN network layer;
- Networking core;
- Ethtool driver;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- KCM (Kernel Connection Multiplexor) sockets driver;
- MAC80211 subsystem;
- Netfilter;
- Network traffic control;
- SCTP protocol;
- Sun RPC protocol;
- TIPC protocol;
- TLS protocol;
- Wireless networking;
- AppArmor security module;
- Simplified Mandatory Access Control Kernel framework;
- SoC audio core drivers;
- USB sound devices;
(CVE-2024-46714, CVE-2024-42288, CVE-2024-42290, CVE-2024-44987,
CVE-2024-41090, CVE-2024-42313, CVE-2024-46689, CVE-2024-46737,
CVE-2024-44946, CVE-2024-44999, CVE-2024-44935, CVE-2024-38602,
CVE-2024-43883, CVE-2024-26607, CVE-2024-41091, CVE-2024-45025,
CVE-2024-42305, CVE-2024-26891, CVE-2024-41073, CVE-2024-44969,
CVE-2024-26641, CVE-2024-46719, CVE-2024-40929, CVE-2024-46721,
CVE-2024-46740, CVE-2024-41012, CVE-2024-42280, CVE-2024-46738,
CVE-2024-46722, CVE-2024-42246, CVE-2024-41063, CVE-2024-41072,
CVE-2024-41068, CVE-2024-43884, CVE-2024-46758, CVE-2024-43861,
CVE-2024-42306, CVE-2024-42285, CVE-2024-41065, CVE-2024-46818,
CVE-2024-43894, CVE-2024-44954, CVE-2024-42310, CVE-2024-46829,
CVE-2023-52614, CVE-2024-47663, CVE-2024-42281, CVE-2024-42297,
CVE-2024-46800, CVE-2024-44960, CVE-2024-44952, CVE-2024-46747,
CVE-2024-42286, CVE-2024-41071, CVE-2024-43893, CVE-2023-52531,
CVE-2024-43860, CVE-2024-46840, CVE-2024-41011, CVE-2024-43890,
CVE-2024-45026, CVE-2024-42292, CVE-2024-27051, CVE-2024-41015,
CVE-2024-47668, CVE-2024-46817, CVE-2024-43846, CVE-2024-44988,
CVE-2024-44944, CVE-2024-43829, CVE-2024-45021, CVE-2024-43914,
CVE-2024-43856, CVE-2024-46673, CVE-2024-46771, CVE-2024-41081,
CVE-2024-43830, CVE-2024-43839, CVE-2024-43853, CVE-2024-47669,
CVE-2024-42244, CVE-2021-47212, CVE-2024-46844, CVE-2024-44965,
CVE-2024-41059, CVE-2024-46783, CVE-2024-42295, CVE-2024-35848,
CVE-2024-41017, CVE-2024-47659, CVE-2024-42309, CVE-2024-26800,
CVE-2024-41064, CVE-2024-43879, CVE-2024-46679, CVE-2024-43854,
CVE-2024-41022, CVE-2024-43858, CVE-2024-46739, CVE-2024-46685,
CVE-2024-42289, CVE-2024-44998, CVE-2024-46761, CVE-2024-46677,
CVE-2024-42131, CVE-2024-46815, CVE-2024-46777, CVE-2024-43880,
CVE-2024-42276, CVE-2024-42265, CVE-2024-46723, CVE-2024-42259,
CVE-2024-45028, CVE-2024-42229, CVE-2024-42283, CVE-2024-44948,
CVE-2024-44995, CVE-2024-46757, CVE-2024-46822, CVE-2024-45006,
CVE-2024-46780, CVE-2024-26668, CVE-2024-42284, CVE-2024-46782,
CVE-2024-46781, CVE-2024-43871, CVE-2024-42304, CVE-2024-42311,
CVE-2024-45003, CVE-2024-46745, CVE-2024-41098, CVE-2024-46750,
CVE-2024-47667, CVE-2024-41020, CVE-2024-26640, CVE-2024-41070,
CVE-2024-42301, CVE-2024-43882, CVE-2024-45008, CVE-2024-26885,
CVE-2024-42287, CVE-2024-46744, CVE-2024-43908, CVE-2024-46798,
CVE-2023-52918, CVE-2024-36484, CVE-2024-43841, CVE-2024-41042,
CVE-2024-38611, CVE-2024-43867, CVE-2024-26669, CVE-2024-42271,
CVE-2024-46756, CVE-2024-44947, CVE-2024-43835, CVE-2024-46676,
CVE-2024-46743, CVE-2024-46759, CVE-2024-46675, CVE-2024-46828,
CVE-2024-46755)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.4.0-1094-bluefield 5.4.0-1094.101
linux-image-5.4.0-1139-azure 5.4.0-1139.146
linux-image-azure-lts-20.04 5.4.0.1139.133
linux-image-bluefield 5.4.0.1094.90
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7088-2
https://ubuntu.com/security/notices/USN-7088-1
CVE-2021-47212, CVE-2022-36402, CVE-2023-52531, CVE-2023-52614,
CVE-2023-52918, CVE-2024-26607, CVE-2024-26640, CVE-2024-26641,
CVE-2024-26668, CVE-2024-26669, CVE-2024-26800, CVE-2024-26885,
CVE-2024-26891, CVE-2024-27051, CVE-2024-35848, CVE-2024-36484,
CVE-2024-38602, CVE-2024-38611, CVE-2024-40929, CVE-2024-41011,
CVE-2024-41012, CVE-2024-41015, CVE-2024-41017, CVE-2024-41020,
CVE-2024-41022, CVE-2024-41042, CVE-2024-41059, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41068, CVE-2024-41070,
CVE-2024-41071, CVE-2024-41072, CVE-2024-41073, CVE-2024-41081,
CVE-2024-41090, CVE-2024-41091, CVE-2024-41098, CVE-2024-42131,
CVE-2024-42229, CVE-2024-42244, CVE-2024-42246, CVE-2024-42259,
CVE-2024-42265, CVE-2024-42271, CVE-2024-42276, CVE-2024-42280,
CVE-2024-42281, CVE-2024-42283, CVE-2024-42284, CVE-2024-42285,
CVE-2024-42286, CVE-2024-42287, CVE-2024-42288, CVE-2024-42289,
CVE-2024-42290, CVE-2024-42292, CVE-2024-42295, CVE-2024-42297,
CVE-2024-42301, CVE-2024-42304, CVE-2024-42305, CVE-2024-42306,
CVE-2024-42309, CVE-2024-42310, CVE-2024-42311, CVE-2024-42313,
CVE-2024-43829, CVE-2024-43830, CVE-2024-43835, CVE-2024-43839,
CVE-2024-43841, CVE-2024-43846, CVE-2024-43853, CVE-2024-43854,
CVE-2024-43856, CVE-2024-43858, CVE-2024-43860, CVE-2024-43861,
CVE-2024-43867, CVE-2024-43871, CVE-2024-43879, CVE-2024-43880,
CVE-2024-43882, CVE-2024-43883, CVE-2024-43884, CVE-2024-43890,
CVE-2024-43893, CVE-2024-43894, CVE-2024-43908, CVE-2024-43914,
CVE-2024-44935, CVE-2024-44944, CVE-2024-44946, CVE-2024-44947,
CVE-2024-44948, CVE-2024-44952, CVE-2024-44954, CVE-2024-44960,
CVE-2024-44965, CVE-2024-44969, CVE-2024-44987, CVE-2024-44988,
CVE-2024-44995, CVE-2024-44998, CVE-2024-44999, CVE-2024-45003,
CVE-2024-45006, CVE-2024-45008, CVE-2024-45021, CVE-2024-45025,
CVE-2024-45026, CVE-2024-45028, CVE-2024-46673, CVE-2024-46675,
CVE-2024-46676, CVE-2024-46677, CVE-2024-46679, CVE-2024-46685,
CVE-2024-46689, CVE-2024-46714, CVE-2024-46719, CVE-2024-46721,
CVE-2024-46722, CVE-2024-46723, CVE-2024-46737, CVE-2024-46738,
CVE-2024-46739, CVE-2024-46740, CVE-2024-46743, CVE-2024-46744,
CVE-2024-46745, CVE-2024-46747, CVE-2024-46750, CVE-2024-46755,
CVE-2024-46756, CVE-2024-46757, CVE-2024-46758, CVE-2024-46759,
CVE-2024-46761, CVE-2024-46771, CVE-2024-46777, CVE-2024-46780,
CVE-2024-46781, CVE-2024-46782, CVE-2024-46783, CVE-2024-46798,
CVE-2024-46800, CVE-2024-46815, CVE-2024-46817, CVE-2024-46818,
CVE-2024-46822, CVE-2024-46828, CVE-2024-46829, CVE-2024-46840,
CVE-2024-46844, CVE-2024-47659, CVE-2024-47663, CVE-2024-47667,
CVE-2024-47668, CVE-2024-47669
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1140.147
https://launchpad.net/ubuntu/+source/linux-bluefield/5.4.0-1095.102
Ubuntu Security Notice USN-7088-2
November 04, 2024
linux-azure, linux-bluefield vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-bluefield: Linux kernel for NVIDIA BlueField platforms
Details:
Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the
Linux kernel contained an integer overflow vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2022-36402)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- PowerPC architecture;
- User-Mode Linux (UML);
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Android drivers;
- Serial ATA and Parallel ATA drivers;
- ATM drivers;
- Drivers core;
- CPU frequency scaling framework;
- Device frequency scaling framework;
- GPU drivers;
- HID subsystem;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Input Device core drivers;
- Input Device (Miscellaneous) drivers;
- IOMMU subsystem;
- IRQ chip drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- EEPROM drivers;
- VMware VMCI Driver;
- MMC subsystem;
- Network drivers;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- Device tree and open firmware driver;
- Parport drivers;
- PCI subsystem;
- Pin controllers subsystem;
- Remote Processor subsystem;
- S/390 drivers;
- SCSI drivers;
- QCOM SoC drivers;
- Direct Digital Synthesis drivers;
- TTY drivers;
- Userspace I/O drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- BTRFS file system;
- File systems infrastructure;
- Ext4 file system;
- F2FS file system;
- JFS file system;
- NILFS2 file system;
- BPF subsystem;
- Core kernel;
- DMA mapping infrastructure;
- Tracing infrastructure;
- Radix Tree data structure library;
- Kernel userspace event delivery library;
- Objagg library;
- Memory management;
- Amateur Radio drivers;
- Bluetooth subsystem;
- CAN network layer;
- Networking core;
- Ethtool driver;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- KCM (Kernel Connection Multiplexor) sockets driver;
- MAC80211 subsystem;
- Netfilter;
- Network traffic control;
- SCTP protocol;
- Sun RPC protocol;
- TIPC protocol;
- TLS protocol;
- Wireless networking;
- AppArmor security module;
- Simplified Mandatory Access Control Kernel framework;
- SoC audio core drivers;
- USB sound devices;
(CVE-2024-46714, CVE-2024-42288, CVE-2024-42290, CVE-2024-44987,
CVE-2024-41090, CVE-2024-42313, CVE-2024-46689, CVE-2024-46737,
CVE-2024-44946, CVE-2024-44999, CVE-2024-44935, CVE-2024-38602,
CVE-2024-43883, CVE-2024-26607, CVE-2024-41091, CVE-2024-45025,
CVE-2024-42305, CVE-2024-26891, CVE-2024-41073, CVE-2024-44969,
CVE-2024-26641, CVE-2024-46719, CVE-2024-40929, CVE-2024-46721,
CVE-2024-46740, CVE-2024-41012, CVE-2024-42280, CVE-2024-46738,
CVE-2024-46722, CVE-2024-42246, CVE-2024-41063, CVE-2024-41072,
CVE-2024-41068, CVE-2024-43884, CVE-2024-46758, CVE-2024-43861,
CVE-2024-42306, CVE-2024-42285, CVE-2024-41065, CVE-2024-46818,
CVE-2024-43894, CVE-2024-44954, CVE-2024-42310, CVE-2024-46829,
CVE-2023-52614, CVE-2024-47663, CVE-2024-42281, CVE-2024-42297,
CVE-2024-46800, CVE-2024-44960, CVE-2024-44952, CVE-2024-46747,
CVE-2024-42286, CVE-2024-41071, CVE-2024-43893, CVE-2023-52531,
CVE-2024-43860, CVE-2024-46840, CVE-2024-41011, CVE-2024-43890,
CVE-2024-45026, CVE-2024-42292, CVE-2024-27051, CVE-2024-41015,
CVE-2024-47668, CVE-2024-46817, CVE-2024-43846, CVE-2024-44988,
CVE-2024-44944, CVE-2024-43829, CVE-2024-45021, CVE-2024-43914,
CVE-2024-43856, CVE-2024-46673, CVE-2024-46771, CVE-2024-41081,
CVE-2024-43830, CVE-2024-43839, CVE-2024-43853, CVE-2024-47669,
CVE-2024-42244, CVE-2021-47212, CVE-2024-46844, CVE-2024-44965,
CVE-2024-41059, CVE-2024-46783, CVE-2024-42295, CVE-2024-35848,
CVE-2024-41017, CVE-2024-47659, CVE-2024-42309, CVE-2024-26800,
CVE-2024-41064, CVE-2024-43879, CVE-2024-46679, CVE-2024-43854,
CVE-2024-41022, CVE-2024-43858, CVE-2024-46739, CVE-2024-46685,
CVE-2024-42289, CVE-2024-44998, CVE-2024-46761, CVE-2024-46677,
CVE-2024-42131, CVE-2024-46815, CVE-2024-46777, CVE-2024-43880,
CVE-2024-42276, CVE-2024-42265, CVE-2024-46723, CVE-2024-42259,
CVE-2024-45028, CVE-2024-42229, CVE-2024-42283, CVE-2024-44948,
CVE-2024-44995, CVE-2024-46757, CVE-2024-46822, CVE-2024-45006,
CVE-2024-46780, CVE-2024-26668, CVE-2024-42284, CVE-2024-46782,
CVE-2024-46781, CVE-2024-43871, CVE-2024-42304, CVE-2024-42311,
CVE-2024-45003, CVE-2024-46745, CVE-2024-41098, CVE-2024-46750,
CVE-2024-47667, CVE-2024-41020, CVE-2024-26640, CVE-2024-41070,
CVE-2024-42301, CVE-2024-43882, CVE-2024-45008, CVE-2024-26885,
CVE-2024-42287, CVE-2024-46744, CVE-2024-43908, CVE-2024-46798,
CVE-2023-52918, CVE-2024-36484, CVE-2024-43841, CVE-2024-41042,
CVE-2024-38611, CVE-2024-43867, CVE-2024-26669, CVE-2024-42271,
CVE-2024-46756, CVE-2024-44947, CVE-2024-43835, CVE-2024-46676,
CVE-2024-46743, CVE-2024-46759, CVE-2024-46675, CVE-2024-46828,
CVE-2024-46755)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.4.0-1094-bluefield 5.4.0-1094.101
linux-image-5.4.0-1139-azure 5.4.0-1139.146
linux-image-azure-lts-20.04 5.4.0.1139.133
linux-image-bluefield 5.4.0.1094.90
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7088-2
https://ubuntu.com/security/notices/USN-7088-1
CVE-2021-47212, CVE-2022-36402, CVE-2023-52531, CVE-2023-52614,
CVE-2023-52918, CVE-2024-26607, CVE-2024-26640, CVE-2024-26641,
CVE-2024-26668, CVE-2024-26669, CVE-2024-26800, CVE-2024-26885,
CVE-2024-26891, CVE-2024-27051, CVE-2024-35848, CVE-2024-36484,
CVE-2024-38602, CVE-2024-38611, CVE-2024-40929, CVE-2024-41011,
CVE-2024-41012, CVE-2024-41015, CVE-2024-41017, CVE-2024-41020,
CVE-2024-41022, CVE-2024-41042, CVE-2024-41059, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41068, CVE-2024-41070,
CVE-2024-41071, CVE-2024-41072, CVE-2024-41073, CVE-2024-41081,
CVE-2024-41090, CVE-2024-41091, CVE-2024-41098, CVE-2024-42131,
CVE-2024-42229, CVE-2024-42244, CVE-2024-42246, CVE-2024-42259,
CVE-2024-42265, CVE-2024-42271, CVE-2024-42276, CVE-2024-42280,
CVE-2024-42281, CVE-2024-42283, CVE-2024-42284, CVE-2024-42285,
CVE-2024-42286, CVE-2024-42287, CVE-2024-42288, CVE-2024-42289,
CVE-2024-42290, CVE-2024-42292, CVE-2024-42295, CVE-2024-42297,
CVE-2024-42301, CVE-2024-42304, CVE-2024-42305, CVE-2024-42306,
CVE-2024-42309, CVE-2024-42310, CVE-2024-42311, CVE-2024-42313,
CVE-2024-43829, CVE-2024-43830, CVE-2024-43835, CVE-2024-43839,
CVE-2024-43841, CVE-2024-43846, CVE-2024-43853, CVE-2024-43854,
CVE-2024-43856, CVE-2024-43858, CVE-2024-43860, CVE-2024-43861,
CVE-2024-43867, CVE-2024-43871, CVE-2024-43879, CVE-2024-43880,
CVE-2024-43882, CVE-2024-43883, CVE-2024-43884, CVE-2024-43890,
CVE-2024-43893, CVE-2024-43894, CVE-2024-43908, CVE-2024-43914,
CVE-2024-44935, CVE-2024-44944, CVE-2024-44946, CVE-2024-44947,
CVE-2024-44948, CVE-2024-44952, CVE-2024-44954, CVE-2024-44960,
CVE-2024-44965, CVE-2024-44969, CVE-2024-44987, CVE-2024-44988,
CVE-2024-44995, CVE-2024-44998, CVE-2024-44999, CVE-2024-45003,
CVE-2024-45006, CVE-2024-45008, CVE-2024-45021, CVE-2024-45025,
CVE-2024-45026, CVE-2024-45028, CVE-2024-46673, CVE-2024-46675,
CVE-2024-46676, CVE-2024-46677, CVE-2024-46679, CVE-2024-46685,
CVE-2024-46689, CVE-2024-46714, CVE-2024-46719, CVE-2024-46721,
CVE-2024-46722, CVE-2024-46723, CVE-2024-46737, CVE-2024-46738,
CVE-2024-46739, CVE-2024-46740, CVE-2024-46743, CVE-2024-46744,
CVE-2024-46745, CVE-2024-46747, CVE-2024-46750, CVE-2024-46755,
CVE-2024-46756, CVE-2024-46757, CVE-2024-46758, CVE-2024-46759,
CVE-2024-46761, CVE-2024-46771, CVE-2024-46777, CVE-2024-46780,
CVE-2024-46781, CVE-2024-46782, CVE-2024-46783, CVE-2024-46798,
CVE-2024-46800, CVE-2024-46815, CVE-2024-46817, CVE-2024-46818,
CVE-2024-46822, CVE-2024-46828, CVE-2024-46829, CVE-2024-46840,
CVE-2024-46844, CVE-2024-47659, CVE-2024-47663, CVE-2024-47667,
CVE-2024-47668, CVE-2024-47669
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1140.147
https://launchpad.net/ubuntu/+source/linux-bluefield/5.4.0-1095.102
Friday, November 1, 2024
[USN-7090-1] Linux kernel vulnerabilities
==========================================================================
Ubuntu Security Notice USN-7090-1
November 01, 2024
linux-azure-6.8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure-6.8: Linux kernel for Microsoft Azure cloud systems
Details:
Chenyuan Yang discovered that the USB Gadget subsystem in the Linux
kernel did not properly check for the device to be enabled before
writing. A local attacker could possibly use this to cause a denial of
service. (CVE-2024-25741)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- MIPS architecture;
- PA-RISC architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- x86 architecture;
- Cryptographic API;
- Serial ATA and Parallel ATA drivers;
- Null block device driver;
- Bluetooth drivers;
- Cdrom driver;
- Clock framework and drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Cirrus firmware drivers;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- Fastrpc Driver;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- NVMEM (Non Volatile Memory) drivers;
- PCI subsystem;
- Pin controllers subsystem;
- x86 platform drivers;
- S/390 drivers;
- SCSI drivers;
- Thermal drivers;
- TTY drivers;
- UFS subsystem;
- USB DSL drivers;
- USB core drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- VFIO drivers;
- VHOST drivers;
- File systems infrastructure;
- BTRFS file system;
- GFS2 file system;
- JFFS2 file system;
- JFS file system;
- Network file systems library;
- Network file system client;
- NILFS2 file system;
- NTFS3 file system;
- SMB network file system;
- Memory management;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- BPF subsystem;
- Core kernel;
- Bluetooth subsystem;
- CAN network layer;
- Ceph Core library;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- MAC80211 subsystem;
- Network traffic control;
- Sun RPC protocol;
- Wireless networking;
- AMD SoC Alsa drivers;
- SoC Audio for Freescale CPUs drivers;
- MediaTek ASoC drivers;
- SoC audio core drivers;
- SOF drivers;
- Sound sequencer drivers;
(CVE-2024-42064, CVE-2024-43858, CVE-2024-42251, CVE-2024-42113,
CVE-2024-41020, CVE-2024-41093, CVE-2024-45016, CVE-2024-42150,
CVE-2024-42069, CVE-2024-42157, CVE-2024-42126, CVE-2024-42144,
CVE-2024-42093, CVE-2024-41035, CVE-2024-41032, CVE-2024-41077,
CVE-2024-42097, CVE-2024-41071, CVE-2024-42227, CVE-2024-42253,
CVE-2024-42237, CVE-2024-41060, CVE-2024-42080, CVE-2024-42068,
CVE-2024-41058, CVE-2024-42140, CVE-2024-42231, CVE-2024-42127,
CVE-2024-42243, CVE-2023-52887, CVE-2024-39486, CVE-2024-41063,
CVE-2024-42128, CVE-2024-42074, CVE-2024-41028, CVE-2024-42110,
CVE-2024-45001, CVE-2024-41090, CVE-2024-41084, CVE-2024-41088,
CVE-2024-42118, CVE-2024-41094, CVE-2024-41091, CVE-2024-41007,
CVE-2024-42280, CVE-2024-41044, CVE-2024-41012, CVE-2024-42063,
CVE-2024-41078, CVE-2024-42082, CVE-2024-41055, CVE-2024-41031,
CVE-2024-42142, CVE-2024-41083, CVE-2024-42145, CVE-2024-41039,
CVE-2024-41019, CVE-2024-42149, CVE-2024-42248, CVE-2024-42111,
CVE-2024-41074, CVE-2024-42096, CVE-2024-42100, CVE-2024-41010,
CVE-2024-43855, CVE-2024-42136, CVE-2024-41054, CVE-2024-41053,
CVE-2024-41061, CVE-2024-42104, CVE-2024-41025, CVE-2024-42129,
CVE-2024-41086, CVE-2024-42133, CVE-2024-42115, CVE-2024-42158,
CVE-2024-42091, CVE-2024-42088, CVE-2024-42161, CVE-2024-42236,
CVE-2024-41065, CVE-2024-41062, CVE-2024-42153, CVE-2024-41030,
CVE-2024-41079, CVE-2023-52888, CVE-2024-42223, CVE-2024-42119,
CVE-2024-42238, CVE-2024-41052, CVE-2024-41064, CVE-2024-42138,
CVE-2024-41081, CVE-2024-41034, CVE-2024-42147, CVE-2024-41095,
CVE-2024-42132, CVE-2024-42137, CVE-2024-42106, CVE-2024-41041,
CVE-2024-41073, CVE-2024-41033, CVE-2024-41075, CVE-2024-42112,
CVE-2024-41070, CVE-2024-42234, CVE-2024-41027, CVE-2024-42105,
CVE-2024-41089, CVE-2024-41098, CVE-2024-42152, CVE-2024-42101,
CVE-2024-41050, CVE-2024-41069, CVE-2024-42120, CVE-2024-42130,
CVE-2024-42084, CVE-2024-41066, CVE-2024-42108, CVE-2024-42087,
CVE-2024-41067, CVE-2024-41023, CVE-2024-41046, CVE-2024-42079,
CVE-2024-42065, CVE-2024-42098, CVE-2024-42070, CVE-2024-41076,
CVE-2024-41082, CVE-2024-41096, CVE-2024-42235, CVE-2024-42085,
CVE-2024-42246, CVE-2024-41049, CVE-2024-42076, CVE-2024-41048,
CVE-2024-41038, CVE-2024-42241, CVE-2024-41092, CVE-2024-42114,
CVE-2024-41036, CVE-2024-41047, CVE-2024-41029, CVE-2024-42092,
CVE-2024-41068, CVE-2024-42067, CVE-2024-42094, CVE-2024-42245,
CVE-2024-41051, CVE-2024-42250, CVE-2024-42151, CVE-2024-41059,
CVE-2024-41056, CVE-2024-42095, CVE-2024-42131, CVE-2024-42271,
CVE-2024-42066, CVE-2024-42240, CVE-2024-41017, CVE-2024-42141,
CVE-2024-41072, CVE-2024-42229, CVE-2024-42239, CVE-2024-42073,
CVE-2024-42124, CVE-2024-41080, CVE-2024-42146, CVE-2024-41018,
CVE-2024-41021, CVE-2024-39487, CVE-2024-42086, CVE-2024-42109,
CVE-2024-41045, CVE-2024-41037, CVE-2024-41097, CVE-2024-42225,
CVE-2024-42102, CVE-2024-42117, CVE-2024-42077, CVE-2024-42230,
CVE-2024-41087, CVE-2024-42089, CVE-2024-42252, CVE-2024-42247,
CVE-2024-41057, CVE-2024-42121, CVE-2024-42232, CVE-2024-42090,
CVE-2024-41042, CVE-2024-42244, CVE-2024-42156, CVE-2024-42135,
CVE-2024-42155, CVE-2024-42103, CVE-2024-41015, CVE-2024-41022,
CVE-2024-41085)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
linux-image-6.8.0-1017-azure 6.8.0-1017.20~22.04.1
linux-image-6.8.0-1017-azure-fde 6.8.0-1017.20~22.04.1
linux-image-azure 6.8.0-1017.20~22.04.1
linux-image-azure-fde 6.8.0-1017.20~22.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7090-1
CVE-2023-52887, CVE-2023-52888, CVE-2024-25741, CVE-2024-39486,
CVE-2024-39487, CVE-2024-41007, CVE-2024-41010, CVE-2024-41012,
CVE-2024-41015, CVE-2024-41017, CVE-2024-41018, CVE-2024-41019,
CVE-2024-41020, CVE-2024-41021, CVE-2024-41022, CVE-2024-41023,
CVE-2024-41025, CVE-2024-41027, CVE-2024-41028, CVE-2024-41029,
CVE-2024-41030, CVE-2024-41031, CVE-2024-41032, CVE-2024-41033,
CVE-2024-41034, CVE-2024-41035, CVE-2024-41036, CVE-2024-41037,
CVE-2024-41038, CVE-2024-41039, CVE-2024-41041, CVE-2024-41042,
CVE-2024-41044, CVE-2024-41045, CVE-2024-41046, CVE-2024-41047,
CVE-2024-41048, CVE-2024-41049, CVE-2024-41050, CVE-2024-41051,
CVE-2024-41052, CVE-2024-41053, CVE-2024-41054, CVE-2024-41055,
CVE-2024-41056, CVE-2024-41057, CVE-2024-41058, CVE-2024-41059,
CVE-2024-41060, CVE-2024-41061, CVE-2024-41062, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41066, CVE-2024-41067,
CVE-2024-41068, CVE-2024-41069, CVE-2024-41070, CVE-2024-41071,
CVE-2024-41072, CVE-2024-41073, CVE-2024-41074, CVE-2024-41075,
CVE-2024-41076, CVE-2024-41077, CVE-2024-41078, CVE-2024-41079,
CVE-2024-41080, CVE-2024-41081, CVE-2024-41082, CVE-2024-41083,
CVE-2024-41084, CVE-2024-41085, CVE-2024-41086, CVE-2024-41087,
CVE-2024-41088, CVE-2024-41089, CVE-2024-41090, CVE-2024-41091,
CVE-2024-41092, CVE-2024-41093, CVE-2024-41094, CVE-2024-41095,
CVE-2024-41096, CVE-2024-41097, CVE-2024-41098, CVE-2024-42063,
CVE-2024-42064, CVE-2024-42065, CVE-2024-42066, CVE-2024-42067,
CVE-2024-42068, CVE-2024-42069, CVE-2024-42070, CVE-2024-42073,
CVE-2024-42074, CVE-2024-42076, CVE-2024-42077, CVE-2024-42079,
CVE-2024-42080, CVE-2024-42082, CVE-2024-42084, CVE-2024-42085,
CVE-2024-42086, CVE-2024-42087, CVE-2024-42088, CVE-2024-42089,
CVE-2024-42090, CVE-2024-42091, CVE-2024-42092, CVE-2024-42093,
CVE-2024-42094, CVE-2024-42095, CVE-2024-42096, CVE-2024-42097,
CVE-2024-42098, CVE-2024-42100, CVE-2024-42101, CVE-2024-42102,
CVE-2024-42103, CVE-2024-42104, CVE-2024-42105, CVE-2024-42106,
CVE-2024-42108, CVE-2024-42109, CVE-2024-42110, CVE-2024-42111,
CVE-2024-42112, CVE-2024-42113, CVE-2024-42114, CVE-2024-42115,
CVE-2024-42117, CVE-2024-42118, CVE-2024-42119, CVE-2024-42120,
CVE-2024-42121, CVE-2024-42124, CVE-2024-42126, CVE-2024-42127,
CVE-2024-42128, CVE-2024-42129, CVE-2024-42130, CVE-2024-42131,
CVE-2024-42132, CVE-2024-42133, CVE-2024-42135, CVE-2024-42136,
CVE-2024-42137, CVE-2024-42138, CVE-2024-42140, CVE-2024-42141,
CVE-2024-42142, CVE-2024-42144, CVE-2024-42145, CVE-2024-42146,
CVE-2024-42147, CVE-2024-42149, CVE-2024-42150, CVE-2024-42151,
CVE-2024-42152, CVE-2024-42153, CVE-2024-42155, CVE-2024-42156,
CVE-2024-42157, CVE-2024-42158, CVE-2024-42161, CVE-2024-42223,
CVE-2024-42225, CVE-2024-42227, CVE-2024-42229, CVE-2024-42230,
CVE-2024-42231, CVE-2024-42232, CVE-2024-42234, CVE-2024-42235,
CVE-2024-42236, CVE-2024-42237, CVE-2024-42238, CVE-2024-42239,
CVE-2024-42240, CVE-2024-42241, CVE-2024-42243, CVE-2024-42244,
CVE-2024-42245, CVE-2024-42246, CVE-2024-42247, CVE-2024-42248,
CVE-2024-42250, CVE-2024-42251, CVE-2024-42252, CVE-2024-42253,
CVE-2024-42271, CVE-2024-42280, CVE-2024-43855, CVE-2024-43858,
CVE-2024-45001, CVE-2024-45016
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure-6.8/6.8.0-1017.20~22.04.1
Ubuntu Security Notice USN-7090-1
November 01, 2024
linux-azure-6.8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure-6.8: Linux kernel for Microsoft Azure cloud systems
Details:
Chenyuan Yang discovered that the USB Gadget subsystem in the Linux
kernel did not properly check for the device to be enabled before
writing. A local attacker could possibly use this to cause a denial of
service. (CVE-2024-25741)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- MIPS architecture;
- PA-RISC architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- x86 architecture;
- Cryptographic API;
- Serial ATA and Parallel ATA drivers;
- Null block device driver;
- Bluetooth drivers;
- Cdrom driver;
- Clock framework and drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Cirrus firmware drivers;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- Fastrpc Driver;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- NVMEM (Non Volatile Memory) drivers;
- PCI subsystem;
- Pin controllers subsystem;
- x86 platform drivers;
- S/390 drivers;
- SCSI drivers;
- Thermal drivers;
- TTY drivers;
- UFS subsystem;
- USB DSL drivers;
- USB core drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- VFIO drivers;
- VHOST drivers;
- File systems infrastructure;
- BTRFS file system;
- GFS2 file system;
- JFFS2 file system;
- JFS file system;
- Network file systems library;
- Network file system client;
- NILFS2 file system;
- NTFS3 file system;
- SMB network file system;
- Memory management;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- BPF subsystem;
- Core kernel;
- Bluetooth subsystem;
- CAN network layer;
- Ceph Core library;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- MAC80211 subsystem;
- Network traffic control;
- Sun RPC protocol;
- Wireless networking;
- AMD SoC Alsa drivers;
- SoC Audio for Freescale CPUs drivers;
- MediaTek ASoC drivers;
- SoC audio core drivers;
- SOF drivers;
- Sound sequencer drivers;
(CVE-2024-42064, CVE-2024-43858, CVE-2024-42251, CVE-2024-42113,
CVE-2024-41020, CVE-2024-41093, CVE-2024-45016, CVE-2024-42150,
CVE-2024-42069, CVE-2024-42157, CVE-2024-42126, CVE-2024-42144,
CVE-2024-42093, CVE-2024-41035, CVE-2024-41032, CVE-2024-41077,
CVE-2024-42097, CVE-2024-41071, CVE-2024-42227, CVE-2024-42253,
CVE-2024-42237, CVE-2024-41060, CVE-2024-42080, CVE-2024-42068,
CVE-2024-41058, CVE-2024-42140, CVE-2024-42231, CVE-2024-42127,
CVE-2024-42243, CVE-2023-52887, CVE-2024-39486, CVE-2024-41063,
CVE-2024-42128, CVE-2024-42074, CVE-2024-41028, CVE-2024-42110,
CVE-2024-45001, CVE-2024-41090, CVE-2024-41084, CVE-2024-41088,
CVE-2024-42118, CVE-2024-41094, CVE-2024-41091, CVE-2024-41007,
CVE-2024-42280, CVE-2024-41044, CVE-2024-41012, CVE-2024-42063,
CVE-2024-41078, CVE-2024-42082, CVE-2024-41055, CVE-2024-41031,
CVE-2024-42142, CVE-2024-41083, CVE-2024-42145, CVE-2024-41039,
CVE-2024-41019, CVE-2024-42149, CVE-2024-42248, CVE-2024-42111,
CVE-2024-41074, CVE-2024-42096, CVE-2024-42100, CVE-2024-41010,
CVE-2024-43855, CVE-2024-42136, CVE-2024-41054, CVE-2024-41053,
CVE-2024-41061, CVE-2024-42104, CVE-2024-41025, CVE-2024-42129,
CVE-2024-41086, CVE-2024-42133, CVE-2024-42115, CVE-2024-42158,
CVE-2024-42091, CVE-2024-42088, CVE-2024-42161, CVE-2024-42236,
CVE-2024-41065, CVE-2024-41062, CVE-2024-42153, CVE-2024-41030,
CVE-2024-41079, CVE-2023-52888, CVE-2024-42223, CVE-2024-42119,
CVE-2024-42238, CVE-2024-41052, CVE-2024-41064, CVE-2024-42138,
CVE-2024-41081, CVE-2024-41034, CVE-2024-42147, CVE-2024-41095,
CVE-2024-42132, CVE-2024-42137, CVE-2024-42106, CVE-2024-41041,
CVE-2024-41073, CVE-2024-41033, CVE-2024-41075, CVE-2024-42112,
CVE-2024-41070, CVE-2024-42234, CVE-2024-41027, CVE-2024-42105,
CVE-2024-41089, CVE-2024-41098, CVE-2024-42152, CVE-2024-42101,
CVE-2024-41050, CVE-2024-41069, CVE-2024-42120, CVE-2024-42130,
CVE-2024-42084, CVE-2024-41066, CVE-2024-42108, CVE-2024-42087,
CVE-2024-41067, CVE-2024-41023, CVE-2024-41046, CVE-2024-42079,
CVE-2024-42065, CVE-2024-42098, CVE-2024-42070, CVE-2024-41076,
CVE-2024-41082, CVE-2024-41096, CVE-2024-42235, CVE-2024-42085,
CVE-2024-42246, CVE-2024-41049, CVE-2024-42076, CVE-2024-41048,
CVE-2024-41038, CVE-2024-42241, CVE-2024-41092, CVE-2024-42114,
CVE-2024-41036, CVE-2024-41047, CVE-2024-41029, CVE-2024-42092,
CVE-2024-41068, CVE-2024-42067, CVE-2024-42094, CVE-2024-42245,
CVE-2024-41051, CVE-2024-42250, CVE-2024-42151, CVE-2024-41059,
CVE-2024-41056, CVE-2024-42095, CVE-2024-42131, CVE-2024-42271,
CVE-2024-42066, CVE-2024-42240, CVE-2024-41017, CVE-2024-42141,
CVE-2024-41072, CVE-2024-42229, CVE-2024-42239, CVE-2024-42073,
CVE-2024-42124, CVE-2024-41080, CVE-2024-42146, CVE-2024-41018,
CVE-2024-41021, CVE-2024-39487, CVE-2024-42086, CVE-2024-42109,
CVE-2024-41045, CVE-2024-41037, CVE-2024-41097, CVE-2024-42225,
CVE-2024-42102, CVE-2024-42117, CVE-2024-42077, CVE-2024-42230,
CVE-2024-41087, CVE-2024-42089, CVE-2024-42252, CVE-2024-42247,
CVE-2024-41057, CVE-2024-42121, CVE-2024-42232, CVE-2024-42090,
CVE-2024-41042, CVE-2024-42244, CVE-2024-42156, CVE-2024-42135,
CVE-2024-42155, CVE-2024-42103, CVE-2024-41015, CVE-2024-41022,
CVE-2024-41085)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
linux-image-6.8.0-1017-azure 6.8.0-1017.20~22.04.1
linux-image-6.8.0-1017-azure-fde 6.8.0-1017.20~22.04.1
linux-image-azure 6.8.0-1017.20~22.04.1
linux-image-azure-fde 6.8.0-1017.20~22.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7090-1
CVE-2023-52887, CVE-2023-52888, CVE-2024-25741, CVE-2024-39486,
CVE-2024-39487, CVE-2024-41007, CVE-2024-41010, CVE-2024-41012,
CVE-2024-41015, CVE-2024-41017, CVE-2024-41018, CVE-2024-41019,
CVE-2024-41020, CVE-2024-41021, CVE-2024-41022, CVE-2024-41023,
CVE-2024-41025, CVE-2024-41027, CVE-2024-41028, CVE-2024-41029,
CVE-2024-41030, CVE-2024-41031, CVE-2024-41032, CVE-2024-41033,
CVE-2024-41034, CVE-2024-41035, CVE-2024-41036, CVE-2024-41037,
CVE-2024-41038, CVE-2024-41039, CVE-2024-41041, CVE-2024-41042,
CVE-2024-41044, CVE-2024-41045, CVE-2024-41046, CVE-2024-41047,
CVE-2024-41048, CVE-2024-41049, CVE-2024-41050, CVE-2024-41051,
CVE-2024-41052, CVE-2024-41053, CVE-2024-41054, CVE-2024-41055,
CVE-2024-41056, CVE-2024-41057, CVE-2024-41058, CVE-2024-41059,
CVE-2024-41060, CVE-2024-41061, CVE-2024-41062, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41066, CVE-2024-41067,
CVE-2024-41068, CVE-2024-41069, CVE-2024-41070, CVE-2024-41071,
CVE-2024-41072, CVE-2024-41073, CVE-2024-41074, CVE-2024-41075,
CVE-2024-41076, CVE-2024-41077, CVE-2024-41078, CVE-2024-41079,
CVE-2024-41080, CVE-2024-41081, CVE-2024-41082, CVE-2024-41083,
CVE-2024-41084, CVE-2024-41085, CVE-2024-41086, CVE-2024-41087,
CVE-2024-41088, CVE-2024-41089, CVE-2024-41090, CVE-2024-41091,
CVE-2024-41092, CVE-2024-41093, CVE-2024-41094, CVE-2024-41095,
CVE-2024-41096, CVE-2024-41097, CVE-2024-41098, CVE-2024-42063,
CVE-2024-42064, CVE-2024-42065, CVE-2024-42066, CVE-2024-42067,
CVE-2024-42068, CVE-2024-42069, CVE-2024-42070, CVE-2024-42073,
CVE-2024-42074, CVE-2024-42076, CVE-2024-42077, CVE-2024-42079,
CVE-2024-42080, CVE-2024-42082, CVE-2024-42084, CVE-2024-42085,
CVE-2024-42086, CVE-2024-42087, CVE-2024-42088, CVE-2024-42089,
CVE-2024-42090, CVE-2024-42091, CVE-2024-42092, CVE-2024-42093,
CVE-2024-42094, CVE-2024-42095, CVE-2024-42096, CVE-2024-42097,
CVE-2024-42098, CVE-2024-42100, CVE-2024-42101, CVE-2024-42102,
CVE-2024-42103, CVE-2024-42104, CVE-2024-42105, CVE-2024-42106,
CVE-2024-42108, CVE-2024-42109, CVE-2024-42110, CVE-2024-42111,
CVE-2024-42112, CVE-2024-42113, CVE-2024-42114, CVE-2024-42115,
CVE-2024-42117, CVE-2024-42118, CVE-2024-42119, CVE-2024-42120,
CVE-2024-42121, CVE-2024-42124, CVE-2024-42126, CVE-2024-42127,
CVE-2024-42128, CVE-2024-42129, CVE-2024-42130, CVE-2024-42131,
CVE-2024-42132, CVE-2024-42133, CVE-2024-42135, CVE-2024-42136,
CVE-2024-42137, CVE-2024-42138, CVE-2024-42140, CVE-2024-42141,
CVE-2024-42142, CVE-2024-42144, CVE-2024-42145, CVE-2024-42146,
CVE-2024-42147, CVE-2024-42149, CVE-2024-42150, CVE-2024-42151,
CVE-2024-42152, CVE-2024-42153, CVE-2024-42155, CVE-2024-42156,
CVE-2024-42157, CVE-2024-42158, CVE-2024-42161, CVE-2024-42223,
CVE-2024-42225, CVE-2024-42227, CVE-2024-42229, CVE-2024-42230,
CVE-2024-42231, CVE-2024-42232, CVE-2024-42234, CVE-2024-42235,
CVE-2024-42236, CVE-2024-42237, CVE-2024-42238, CVE-2024-42239,
CVE-2024-42240, CVE-2024-42241, CVE-2024-42243, CVE-2024-42244,
CVE-2024-42245, CVE-2024-42246, CVE-2024-42247, CVE-2024-42248,
CVE-2024-42250, CVE-2024-42251, CVE-2024-42252, CVE-2024-42253,
CVE-2024-42271, CVE-2024-42280, CVE-2024-43855, CVE-2024-43858,
CVE-2024-45001, CVE-2024-45016
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure-6.8/6.8.0-1017.20~22.04.1
[USN-7089-1] Linux kernel vulnerabilities
==========================================================================
Ubuntu Security Notice USN-7089-1
November 01, 2024
linux, linux-azure-6.8, linux-gcp-6.8, linux-hwe-6.8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-azure-6.8: Linux kernel for Microsoft Azure cloud systems
- linux-gcp-6.8: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe-6.8: Linux hardware enablement (HWE) kernel
Details:
Chenyuan Yang discovered that the USB Gadget subsystem in the Linux
kernel did not properly check for the device to be enabled before
writing. A local attacker could possibly use this to cause a denial of
service. (CVE-2024-25741)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- MIPS architecture;
- PA-RISC architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- x86 architecture;
- Cryptographic API;
- Serial ATA and Parallel ATA drivers;
- Null block device driver;
- Bluetooth drivers;
- Cdrom driver;
- Clock framework and drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Cirrus firmware drivers;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- Fastrpc Driver;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- NVMEM (Non Volatile Memory) drivers;
- PCI subsystem;
- Pin controllers subsystem;
- x86 platform drivers;
- S/390 drivers;
- SCSI drivers;
- Thermal drivers;
- TTY drivers;
- UFS subsystem;
- USB DSL drivers;
- USB core drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- VFIO drivers;
- VHOST drivers;
- File systems infrastructure;
- BTRFS file system;
- GFS2 file system;
- JFFS2 file system;
- JFS file system;
- Network file systems library;
- Network file system client;
- NILFS2 file system;
- NTFS3 file system;
- SMB network file system;
- Memory management;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- BPF subsystem;
- Core kernel;
- Bluetooth subsystem;
- CAN network layer;
- Ceph Core library;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- MAC80211 subsystem;
- Network traffic control;
- Sun RPC protocol;
- Wireless networking;
- AMD SoC Alsa drivers;
- SoC Audio for Freescale CPUs drivers;
- MediaTek ASoC drivers;
- SoC audio core drivers;
- SOF drivers;
- Sound sequencer drivers;
(CVE-2024-41079, CVE-2024-41058, CVE-2024-41029, CVE-2024-42253,
CVE-2024-41075, CVE-2024-42280, CVE-2024-42102, CVE-2024-41055,
CVE-2024-41025, CVE-2024-42124, CVE-2024-41060, CVE-2024-41027,
CVE-2024-42145, CVE-2024-42146, CVE-2024-42251, CVE-2024-41081,
CVE-2024-42065, CVE-2024-42129, CVE-2024-41031, CVE-2024-41035,
CVE-2024-41047, CVE-2023-52888, CVE-2024-42248, CVE-2024-41039,
CVE-2024-42119, CVE-2024-41038, CVE-2024-42150, CVE-2024-42073,
CVE-2024-42089, CVE-2024-41007, CVE-2024-42120, CVE-2024-42069,
CVE-2024-41096, CVE-2024-42153, CVE-2024-41012, CVE-2024-42151,
CVE-2024-42241, CVE-2024-42126, CVE-2024-42092, CVE-2024-42231,
CVE-2024-41032, CVE-2024-41076, CVE-2024-42136, CVE-2024-41078,
CVE-2024-41068, CVE-2024-41070, CVE-2024-41091, CVE-2024-42063,
CVE-2024-42157, CVE-2024-42118, CVE-2024-41046, CVE-2024-41023,
CVE-2024-42094, CVE-2024-41042, CVE-2024-41034, CVE-2024-42096,
CVE-2024-42105, CVE-2024-41051, CVE-2024-42239, CVE-2024-42117,
CVE-2024-41019, CVE-2024-41033, CVE-2024-42223, CVE-2024-41098,
CVE-2024-41052, CVE-2024-41036, CVE-2024-41087, CVE-2024-42115,
CVE-2024-41057, CVE-2024-42161, CVE-2024-42240, CVE-2024-41093,
CVE-2024-42097, CVE-2024-42077, CVE-2024-41062, CVE-2024-42156,
CVE-2024-41077, CVE-2024-42235, CVE-2024-41085, CVE-2023-52887,
CVE-2024-42237, CVE-2024-41061, CVE-2024-41073, CVE-2024-42087,
CVE-2024-41086, CVE-2024-41044, CVE-2024-41066, CVE-2024-42128,
CVE-2024-42144, CVE-2024-42227, CVE-2024-41020, CVE-2024-41015,
CVE-2024-42232, CVE-2024-41072, CVE-2024-41030, CVE-2024-42098,
CVE-2024-42121, CVE-2024-42080, CVE-2024-41071, CVE-2024-42225,
CVE-2024-42064, CVE-2024-42246, CVE-2024-42113, CVE-2024-41082,
CVE-2024-42095, CVE-2024-41080, CVE-2024-41056, CVE-2024-42147,
CVE-2024-41069, CVE-2024-42135, CVE-2024-42245, CVE-2024-42244,
CVE-2024-42271, CVE-2024-41084, CVE-2024-42234, CVE-2024-41064,
CVE-2024-42108, CVE-2024-41090, CVE-2024-42079, CVE-2024-42138,
CVE-2024-42127, CVE-2024-42149, CVE-2024-41067, CVE-2024-42130,
CVE-2024-42086, CVE-2024-41045, CVE-2024-42088, CVE-2024-42131,
CVE-2024-41063, CVE-2024-42111, CVE-2024-41088, CVE-2024-42110,
CVE-2024-41074, CVE-2024-41041, CVE-2024-39487, CVE-2024-42076,
CVE-2024-42091, CVE-2024-42132, CVE-2024-42100, CVE-2024-41010,
CVE-2024-42093, CVE-2024-41048, CVE-2024-41059, CVE-2024-42137,
CVE-2024-41065, CVE-2024-42067, CVE-2024-42140, CVE-2024-42250,
CVE-2024-42084, CVE-2024-42155, CVE-2024-41021, CVE-2024-41089,
CVE-2024-42106, CVE-2024-41083, CVE-2024-42112, CVE-2024-42101,
CVE-2024-42229, CVE-2024-41053, CVE-2024-42074, CVE-2024-42252,
CVE-2024-41018, CVE-2024-41095, CVE-2024-42090, CVE-2024-41097,
CVE-2024-42236, CVE-2024-42109, CVE-2024-42158, CVE-2024-43858,
CVE-2024-42133, CVE-2024-42066, CVE-2024-41094, CVE-2024-39486,
CVE-2024-41050, CVE-2024-41028, CVE-2024-42114, CVE-2024-41049,
CVE-2024-42070, CVE-2024-42243, CVE-2024-41092, CVE-2024-43855,
CVE-2024-42103, CVE-2024-41022, CVE-2024-42142, CVE-2024-42238,
CVE-2024-42152, CVE-2024-41037, CVE-2024-42230, CVE-2024-42082,
CVE-2024-42085, CVE-2024-42104, CVE-2024-41017, CVE-2024-41054,
CVE-2024-42068, CVE-2024-42141, CVE-2024-42247)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
linux-image-6.8.0-48-generic 6.8.0-48.48
linux-image-6.8.0-48-generic-64k 6.8.0-48.48
linux-image-generic 6.8.0-48.48
linux-image-generic-64k 6.8.0-48.48
linux-image-generic-64k-hwe-24.04 6.8.0-48.48
linux-image-generic-hwe-24.04 6.8.0-48.48
linux-image-generic-lpae 6.8.0-48.48
linux-image-kvm 6.8.0-48.48
linux-image-virtual 6.8.0-48.48
linux-image-virtual-hwe-24.04 6.8.0-48.48
Ubuntu 22.04 LTS
linux-image-6.8.0-1017-azure 6.8.0-1017.20~22.04.1
linux-image-6.8.0-1017-azure-fde 6.8.0-1017.20~22.04.1
linux-image-6.8.0-1017-gcp 6.8.0-1017.19~22.04.1
linux-image-6.8.0-48-generic 6.8.0-48.48~22.04.1
linux-image-6.8.0-48-generic-64k 6.8.0-48.48~22.04.1
linux-image-azure 6.8.0-1017.20~22.04.1
linux-image-azure-fde 6.8.0-1017.20~22.04.1
linux-image-gcp 6.8.0-1017.19~22.04.1
linux-image-generic-64k-hwe-22.04 6.8.0-48.48~22.04.1
linux-image-generic-hwe-22.04 6.8.0-48.48~22.04.1
linux-image-oem-22.04 6.8.0-48.48~22.04.1
linux-image-oem-22.04a 6.8.0-48.48~22.04.1
linux-image-oem-22.04b 6.8.0-48.48~22.04.1
linux-image-oem-22.04c 6.8.0-48.48~22.04.1
linux-image-oem-22.04d 6.8.0-48.48~22.04.1
linux-image-virtual-hwe-22.04 6.8.0-48.48~22.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7089-1
CVE-2023-52887, CVE-2023-52888, CVE-2024-25741, CVE-2024-39486,
CVE-2024-39487, CVE-2024-41007, CVE-2024-41010, CVE-2024-41012,
CVE-2024-41015, CVE-2024-41017, CVE-2024-41018, CVE-2024-41019,
CVE-2024-41020, CVE-2024-41021, CVE-2024-41022, CVE-2024-41023,
CVE-2024-41025, CVE-2024-41027, CVE-2024-41028, CVE-2024-41029,
CVE-2024-41030, CVE-2024-41031, CVE-2024-41032, CVE-2024-41033,
CVE-2024-41034, CVE-2024-41035, CVE-2024-41036, CVE-2024-41037,
CVE-2024-41038, CVE-2024-41039, CVE-2024-41041, CVE-2024-41042,
CVE-2024-41044, CVE-2024-41045, CVE-2024-41046, CVE-2024-41047,
CVE-2024-41048, CVE-2024-41049, CVE-2024-41050, CVE-2024-41051,
CVE-2024-41052, CVE-2024-41053, CVE-2024-41054, CVE-2024-41055,
CVE-2024-41056, CVE-2024-41057, CVE-2024-41058, CVE-2024-41059,
CVE-2024-41060, CVE-2024-41061, CVE-2024-41062, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41066, CVE-2024-41067,
CVE-2024-41068, CVE-2024-41069, CVE-2024-41070, CVE-2024-41071,
CVE-2024-41072, CVE-2024-41073, CVE-2024-41074, CVE-2024-41075,
CVE-2024-41076, CVE-2024-41077, CVE-2024-41078, CVE-2024-41079,
CVE-2024-41080, CVE-2024-41081, CVE-2024-41082, CVE-2024-41083,
CVE-2024-41084, CVE-2024-41085, CVE-2024-41086, CVE-2024-41087,
CVE-2024-41088, CVE-2024-41089, CVE-2024-41090, CVE-2024-41091,
CVE-2024-41092, CVE-2024-41093, CVE-2024-41094, CVE-2024-41095,
CVE-2024-41096, CVE-2024-41097, CVE-2024-41098, CVE-2024-42063,
CVE-2024-42064, CVE-2024-42065, CVE-2024-42066, CVE-2024-42067,
CVE-2024-42068, CVE-2024-42069, CVE-2024-42070, CVE-2024-42073,
CVE-2024-42074, CVE-2024-42076, CVE-2024-42077, CVE-2024-42079,
CVE-2024-42080, CVE-2024-42082, CVE-2024-42084, CVE-2024-42085,
CVE-2024-42086, CVE-2024-42087, CVE-2024-42088, CVE-2024-42089,
CVE-2024-42090, CVE-2024-42091, CVE-2024-42092, CVE-2024-42093,
CVE-2024-42094, CVE-2024-42095, CVE-2024-42096, CVE-2024-42097,
CVE-2024-42098, CVE-2024-42100, CVE-2024-42101, CVE-2024-42102,
CVE-2024-42103, CVE-2024-42104, CVE-2024-42105, CVE-2024-42106,
CVE-2024-42108, CVE-2024-42109, CVE-2024-42110, CVE-2024-42111,
CVE-2024-42112, CVE-2024-42113, CVE-2024-42114, CVE-2024-42115,
CVE-2024-42117, CVE-2024-42118, CVE-2024-42119, CVE-2024-42120,
CVE-2024-42121, CVE-2024-42124, CVE-2024-42126, CVE-2024-42127,
CVE-2024-42128, CVE-2024-42129, CVE-2024-42130, CVE-2024-42131,
CVE-2024-42132, CVE-2024-42133, CVE-2024-42135, CVE-2024-42136,
CVE-2024-42137, CVE-2024-42138, CVE-2024-42140, CVE-2024-42141,
CVE-2024-42142, CVE-2024-42144, CVE-2024-42145, CVE-2024-42146,
CVE-2024-42147, CVE-2024-42149, CVE-2024-42150, CVE-2024-42151,
CVE-2024-42152, CVE-2024-42153, CVE-2024-42155, CVE-2024-42156,
CVE-2024-42157, CVE-2024-42158, CVE-2024-42161, CVE-2024-42223,
CVE-2024-42225, CVE-2024-42227, CVE-2024-42229, CVE-2024-42230,
CVE-2024-42231, CVE-2024-42232, CVE-2024-42234, CVE-2024-42235,
CVE-2024-42236, CVE-2024-42237, CVE-2024-42238, CVE-2024-42239,
CVE-2024-42240, CVE-2024-42241, CVE-2024-42243, CVE-2024-42244,
CVE-2024-42245, CVE-2024-42246, CVE-2024-42247, CVE-2024-42248,
CVE-2024-42250, CVE-2024-42251, CVE-2024-42252, CVE-2024-42253,
CVE-2024-42271, CVE-2024-42280, CVE-2024-43855, CVE-2024-43858
Package Information:
https://launchpad.net/ubuntu/+source/linux/6.8.0-48.48
https://launchpad.net/ubuntu/+source/linux-azure-6.8/6.8.0-1017.20~22.04.1
https://launchpad.net/ubuntu/+source/linux-gcp-6.8/6.8.0-1017.19~22.04.1
https://launchpad.net/ubuntu/+source/linux-hwe-6.8/6.8.0-48.48~22.04.1
Ubuntu Security Notice USN-7089-1
November 01, 2024
linux, linux-azure-6.8, linux-gcp-6.8, linux-hwe-6.8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-azure-6.8: Linux kernel for Microsoft Azure cloud systems
- linux-gcp-6.8: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe-6.8: Linux hardware enablement (HWE) kernel
Details:
Chenyuan Yang discovered that the USB Gadget subsystem in the Linux
kernel did not properly check for the device to be enabled before
writing. A local attacker could possibly use this to cause a denial of
service. (CVE-2024-25741)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- MIPS architecture;
- PA-RISC architecture;
- PowerPC architecture;
- RISC-V architecture;
- S390 architecture;
- x86 architecture;
- Cryptographic API;
- Serial ATA and Parallel ATA drivers;
- Null block device driver;
- Bluetooth drivers;
- Cdrom driver;
- Clock framework and drivers;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Cirrus firmware drivers;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- ISDN/mISDN subsystem;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- Fastrpc Driver;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- Near Field Communication (NFC) drivers;
- NVME drivers;
- NVMEM (Non Volatile Memory) drivers;
- PCI subsystem;
- Pin controllers subsystem;
- x86 platform drivers;
- S/390 drivers;
- SCSI drivers;
- Thermal drivers;
- TTY drivers;
- UFS subsystem;
- USB DSL drivers;
- USB core drivers;
- DesignWare USB3 driver;
- USB Gadget drivers;
- USB Serial drivers;
- VFIO drivers;
- VHOST drivers;
- File systems infrastructure;
- BTRFS file system;
- GFS2 file system;
- JFFS2 file system;
- JFS file system;
- Network file systems library;
- Network file system client;
- NILFS2 file system;
- NTFS3 file system;
- SMB network file system;
- Memory management;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- BPF subsystem;
- Core kernel;
- Bluetooth subsystem;
- CAN network layer;
- Ceph Core library;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- IUCV driver;
- MAC80211 subsystem;
- Network traffic control;
- Sun RPC protocol;
- Wireless networking;
- AMD SoC Alsa drivers;
- SoC Audio for Freescale CPUs drivers;
- MediaTek ASoC drivers;
- SoC audio core drivers;
- SOF drivers;
- Sound sequencer drivers;
(CVE-2024-41079, CVE-2024-41058, CVE-2024-41029, CVE-2024-42253,
CVE-2024-41075, CVE-2024-42280, CVE-2024-42102, CVE-2024-41055,
CVE-2024-41025, CVE-2024-42124, CVE-2024-41060, CVE-2024-41027,
CVE-2024-42145, CVE-2024-42146, CVE-2024-42251, CVE-2024-41081,
CVE-2024-42065, CVE-2024-42129, CVE-2024-41031, CVE-2024-41035,
CVE-2024-41047, CVE-2023-52888, CVE-2024-42248, CVE-2024-41039,
CVE-2024-42119, CVE-2024-41038, CVE-2024-42150, CVE-2024-42073,
CVE-2024-42089, CVE-2024-41007, CVE-2024-42120, CVE-2024-42069,
CVE-2024-41096, CVE-2024-42153, CVE-2024-41012, CVE-2024-42151,
CVE-2024-42241, CVE-2024-42126, CVE-2024-42092, CVE-2024-42231,
CVE-2024-41032, CVE-2024-41076, CVE-2024-42136, CVE-2024-41078,
CVE-2024-41068, CVE-2024-41070, CVE-2024-41091, CVE-2024-42063,
CVE-2024-42157, CVE-2024-42118, CVE-2024-41046, CVE-2024-41023,
CVE-2024-42094, CVE-2024-41042, CVE-2024-41034, CVE-2024-42096,
CVE-2024-42105, CVE-2024-41051, CVE-2024-42239, CVE-2024-42117,
CVE-2024-41019, CVE-2024-41033, CVE-2024-42223, CVE-2024-41098,
CVE-2024-41052, CVE-2024-41036, CVE-2024-41087, CVE-2024-42115,
CVE-2024-41057, CVE-2024-42161, CVE-2024-42240, CVE-2024-41093,
CVE-2024-42097, CVE-2024-42077, CVE-2024-41062, CVE-2024-42156,
CVE-2024-41077, CVE-2024-42235, CVE-2024-41085, CVE-2023-52887,
CVE-2024-42237, CVE-2024-41061, CVE-2024-41073, CVE-2024-42087,
CVE-2024-41086, CVE-2024-41044, CVE-2024-41066, CVE-2024-42128,
CVE-2024-42144, CVE-2024-42227, CVE-2024-41020, CVE-2024-41015,
CVE-2024-42232, CVE-2024-41072, CVE-2024-41030, CVE-2024-42098,
CVE-2024-42121, CVE-2024-42080, CVE-2024-41071, CVE-2024-42225,
CVE-2024-42064, CVE-2024-42246, CVE-2024-42113, CVE-2024-41082,
CVE-2024-42095, CVE-2024-41080, CVE-2024-41056, CVE-2024-42147,
CVE-2024-41069, CVE-2024-42135, CVE-2024-42245, CVE-2024-42244,
CVE-2024-42271, CVE-2024-41084, CVE-2024-42234, CVE-2024-41064,
CVE-2024-42108, CVE-2024-41090, CVE-2024-42079, CVE-2024-42138,
CVE-2024-42127, CVE-2024-42149, CVE-2024-41067, CVE-2024-42130,
CVE-2024-42086, CVE-2024-41045, CVE-2024-42088, CVE-2024-42131,
CVE-2024-41063, CVE-2024-42111, CVE-2024-41088, CVE-2024-42110,
CVE-2024-41074, CVE-2024-41041, CVE-2024-39487, CVE-2024-42076,
CVE-2024-42091, CVE-2024-42132, CVE-2024-42100, CVE-2024-41010,
CVE-2024-42093, CVE-2024-41048, CVE-2024-41059, CVE-2024-42137,
CVE-2024-41065, CVE-2024-42067, CVE-2024-42140, CVE-2024-42250,
CVE-2024-42084, CVE-2024-42155, CVE-2024-41021, CVE-2024-41089,
CVE-2024-42106, CVE-2024-41083, CVE-2024-42112, CVE-2024-42101,
CVE-2024-42229, CVE-2024-41053, CVE-2024-42074, CVE-2024-42252,
CVE-2024-41018, CVE-2024-41095, CVE-2024-42090, CVE-2024-41097,
CVE-2024-42236, CVE-2024-42109, CVE-2024-42158, CVE-2024-43858,
CVE-2024-42133, CVE-2024-42066, CVE-2024-41094, CVE-2024-39486,
CVE-2024-41050, CVE-2024-41028, CVE-2024-42114, CVE-2024-41049,
CVE-2024-42070, CVE-2024-42243, CVE-2024-41092, CVE-2024-43855,
CVE-2024-42103, CVE-2024-41022, CVE-2024-42142, CVE-2024-42238,
CVE-2024-42152, CVE-2024-41037, CVE-2024-42230, CVE-2024-42082,
CVE-2024-42085, CVE-2024-42104, CVE-2024-41017, CVE-2024-41054,
CVE-2024-42068, CVE-2024-42141, CVE-2024-42247)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
linux-image-6.8.0-48-generic 6.8.0-48.48
linux-image-6.8.0-48-generic-64k 6.8.0-48.48
linux-image-generic 6.8.0-48.48
linux-image-generic-64k 6.8.0-48.48
linux-image-generic-64k-hwe-24.04 6.8.0-48.48
linux-image-generic-hwe-24.04 6.8.0-48.48
linux-image-generic-lpae 6.8.0-48.48
linux-image-kvm 6.8.0-48.48
linux-image-virtual 6.8.0-48.48
linux-image-virtual-hwe-24.04 6.8.0-48.48
Ubuntu 22.04 LTS
linux-image-6.8.0-1017-azure 6.8.0-1017.20~22.04.1
linux-image-6.8.0-1017-azure-fde 6.8.0-1017.20~22.04.1
linux-image-6.8.0-1017-gcp 6.8.0-1017.19~22.04.1
linux-image-6.8.0-48-generic 6.8.0-48.48~22.04.1
linux-image-6.8.0-48-generic-64k 6.8.0-48.48~22.04.1
linux-image-azure 6.8.0-1017.20~22.04.1
linux-image-azure-fde 6.8.0-1017.20~22.04.1
linux-image-gcp 6.8.0-1017.19~22.04.1
linux-image-generic-64k-hwe-22.04 6.8.0-48.48~22.04.1
linux-image-generic-hwe-22.04 6.8.0-48.48~22.04.1
linux-image-oem-22.04 6.8.0-48.48~22.04.1
linux-image-oem-22.04a 6.8.0-48.48~22.04.1
linux-image-oem-22.04b 6.8.0-48.48~22.04.1
linux-image-oem-22.04c 6.8.0-48.48~22.04.1
linux-image-oem-22.04d 6.8.0-48.48~22.04.1
linux-image-virtual-hwe-22.04 6.8.0-48.48~22.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7089-1
CVE-2023-52887, CVE-2023-52888, CVE-2024-25741, CVE-2024-39486,
CVE-2024-39487, CVE-2024-41007, CVE-2024-41010, CVE-2024-41012,
CVE-2024-41015, CVE-2024-41017, CVE-2024-41018, CVE-2024-41019,
CVE-2024-41020, CVE-2024-41021, CVE-2024-41022, CVE-2024-41023,
CVE-2024-41025, CVE-2024-41027, CVE-2024-41028, CVE-2024-41029,
CVE-2024-41030, CVE-2024-41031, CVE-2024-41032, CVE-2024-41033,
CVE-2024-41034, CVE-2024-41035, CVE-2024-41036, CVE-2024-41037,
CVE-2024-41038, CVE-2024-41039, CVE-2024-41041, CVE-2024-41042,
CVE-2024-41044, CVE-2024-41045, CVE-2024-41046, CVE-2024-41047,
CVE-2024-41048, CVE-2024-41049, CVE-2024-41050, CVE-2024-41051,
CVE-2024-41052, CVE-2024-41053, CVE-2024-41054, CVE-2024-41055,
CVE-2024-41056, CVE-2024-41057, CVE-2024-41058, CVE-2024-41059,
CVE-2024-41060, CVE-2024-41061, CVE-2024-41062, CVE-2024-41063,
CVE-2024-41064, CVE-2024-41065, CVE-2024-41066, CVE-2024-41067,
CVE-2024-41068, CVE-2024-41069, CVE-2024-41070, CVE-2024-41071,
CVE-2024-41072, CVE-2024-41073, CVE-2024-41074, CVE-2024-41075,
CVE-2024-41076, CVE-2024-41077, CVE-2024-41078, CVE-2024-41079,
CVE-2024-41080, CVE-2024-41081, CVE-2024-41082, CVE-2024-41083,
CVE-2024-41084, CVE-2024-41085, CVE-2024-41086, CVE-2024-41087,
CVE-2024-41088, CVE-2024-41089, CVE-2024-41090, CVE-2024-41091,
CVE-2024-41092, CVE-2024-41093, CVE-2024-41094, CVE-2024-41095,
CVE-2024-41096, CVE-2024-41097, CVE-2024-41098, CVE-2024-42063,
CVE-2024-42064, CVE-2024-42065, CVE-2024-42066, CVE-2024-42067,
CVE-2024-42068, CVE-2024-42069, CVE-2024-42070, CVE-2024-42073,
CVE-2024-42074, CVE-2024-42076, CVE-2024-42077, CVE-2024-42079,
CVE-2024-42080, CVE-2024-42082, CVE-2024-42084, CVE-2024-42085,
CVE-2024-42086, CVE-2024-42087, CVE-2024-42088, CVE-2024-42089,
CVE-2024-42090, CVE-2024-42091, CVE-2024-42092, CVE-2024-42093,
CVE-2024-42094, CVE-2024-42095, CVE-2024-42096, CVE-2024-42097,
CVE-2024-42098, CVE-2024-42100, CVE-2024-42101, CVE-2024-42102,
CVE-2024-42103, CVE-2024-42104, CVE-2024-42105, CVE-2024-42106,
CVE-2024-42108, CVE-2024-42109, CVE-2024-42110, CVE-2024-42111,
CVE-2024-42112, CVE-2024-42113, CVE-2024-42114, CVE-2024-42115,
CVE-2024-42117, CVE-2024-42118, CVE-2024-42119, CVE-2024-42120,
CVE-2024-42121, CVE-2024-42124, CVE-2024-42126, CVE-2024-42127,
CVE-2024-42128, CVE-2024-42129, CVE-2024-42130, CVE-2024-42131,
CVE-2024-42132, CVE-2024-42133, CVE-2024-42135, CVE-2024-42136,
CVE-2024-42137, CVE-2024-42138, CVE-2024-42140, CVE-2024-42141,
CVE-2024-42142, CVE-2024-42144, CVE-2024-42145, CVE-2024-42146,
CVE-2024-42147, CVE-2024-42149, CVE-2024-42150, CVE-2024-42151,
CVE-2024-42152, CVE-2024-42153, CVE-2024-42155, CVE-2024-42156,
CVE-2024-42157, CVE-2024-42158, CVE-2024-42161, CVE-2024-42223,
CVE-2024-42225, CVE-2024-42227, CVE-2024-42229, CVE-2024-42230,
CVE-2024-42231, CVE-2024-42232, CVE-2024-42234, CVE-2024-42235,
CVE-2024-42236, CVE-2024-42237, CVE-2024-42238, CVE-2024-42239,
CVE-2024-42240, CVE-2024-42241, CVE-2024-42243, CVE-2024-42244,
CVE-2024-42245, CVE-2024-42246, CVE-2024-42247, CVE-2024-42248,
CVE-2024-42250, CVE-2024-42251, CVE-2024-42252, CVE-2024-42253,
CVE-2024-42271, CVE-2024-42280, CVE-2024-43855, CVE-2024-43858
Package Information:
https://launchpad.net/ubuntu/+source/linux/6.8.0-48.48
https://launchpad.net/ubuntu/+source/linux-azure-6.8/6.8.0-1017.20~22.04.1
https://launchpad.net/ubuntu/+source/linux-gcp-6.8/6.8.0-1017.19~22.04.1
https://launchpad.net/ubuntu/+source/linux-hwe-6.8/6.8.0-48.48~22.04.1
F42 Change Proposal: dropping Of cert.pem file (System-Wide)
Wiki - https://fedoraproject.org/wiki/Changes/dropingOfCertPemFile
Discussion thread -
https://discussion.fedoraproject.org/t/f42-change-proposal-dropping-of-cert-pem-file-system-wide/135119
This is a proposed Change for Fedora Linux.
This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.
== Summary ==
In order to increase the performance of OpenSSL by default using
directory-hash format we need to drop the /etc/pki/tls/cert.pem file
to prevent it from being loaded by default.
== Owner ==
* Name: [[User:Fkrenzel| František Krenželok]]
* Email: fkrenzel@redhat.com
== Detailed Description ==
In order to improve the loading time of OpenSSL, a directory-hash
support was added to ca-certificates. In order for OpenSSL to use the
directory-hash format by default we need to stop it from trying to
load /etc/pki/tls/cert.pem by deleting it.
== Feedback ==
== Benefit to Fedora ==
Applications using OpenSSL(possibly other libraries as well) will
benefit from much faster initialization of OpenSSL.
== Scope ==
* Other developers:
Any package loading the root certificates from `/etc/pki/tls/cert.pem`
file need to preferably use the defaults of the library or if they
must, use the `/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem` file
instead.
* Release engineering: [https://pagure.io/releng/issues #Releng issue number]
* Policies and guidelines: N/A (not needed for this Change)
* Trademark approval: N/A (not needed for this Change)
* Alignment with the Fedora Strategy: neither does nor doesn't
== Upgrade/compatibility impact ==
Once this change is intergrated, the packages/software using
`/etc/pki/tls/cert.pem` as a root certificate bundle file might
encounter connectivity issues.
== How To Test ==
Target behavior: OpenSSL initialization takes less time when the file
isn't present compared to it being there.
1. The following will create a symlink for testing after the change
has been integrated(i.e. the `.../tls/cert.pem` file is missing)
`ln -s /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem /etc/pki/tls/cert.pem`
2. Test the time of OpenSSL initialization or a package using it with
and without the aforementioned symlink.
(If there is no difference for package then it is most likely due to
OpenSSL not being configured to search for certs in default location)
== User Experience ==
Packages using a OpenSSL will have faster initialization time.
== Dependencies ==
Any package using `/etc/pki/tls/cert.pem` file are affected. It is
required that the maintainers change this so that user experience is
not compromised.
== Contingency Plan ==
* Contingency mechanism: We will postpone the change if majority or
critical package owners will be unable to make appropriate changes.
* Contingency deadline: before end of beta freeze(2025-02-18).
* Blocks release? The feature doesn't block release.
== Documentation ==
The change is documented as a part of ca-certificates package changelog.
== Release Notes ==
The /etc/pki/tls/cert.pem file has been deprecated
--
Aoife Moloney
Fedora Operations Architect
Fedora Project
Matrix: @amoloney:fedora.im
IRC: amoloney
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Discussion thread -
https://discussion.fedoraproject.org/t/f42-change-proposal-dropping-of-cert-pem-file-system-wide/135119
This is a proposed Change for Fedora Linux.
This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.
== Summary ==
In order to increase the performance of OpenSSL by default using
directory-hash format we need to drop the /etc/pki/tls/cert.pem file
to prevent it from being loaded by default.
== Owner ==
* Name: [[User:Fkrenzel| František Krenželok]]
* Email: fkrenzel@redhat.com
== Detailed Description ==
In order to improve the loading time of OpenSSL, a directory-hash
support was added to ca-certificates. In order for OpenSSL to use the
directory-hash format by default we need to stop it from trying to
load /etc/pki/tls/cert.pem by deleting it.
== Feedback ==
== Benefit to Fedora ==
Applications using OpenSSL(possibly other libraries as well) will
benefit from much faster initialization of OpenSSL.
== Scope ==
* Other developers:
Any package loading the root certificates from `/etc/pki/tls/cert.pem`
file need to preferably use the defaults of the library or if they
must, use the `/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem` file
instead.
* Release engineering: [https://pagure.io/releng/issues #Releng issue number]
* Policies and guidelines: N/A (not needed for this Change)
* Trademark approval: N/A (not needed for this Change)
* Alignment with the Fedora Strategy: neither does nor doesn't
== Upgrade/compatibility impact ==
Once this change is intergrated, the packages/software using
`/etc/pki/tls/cert.pem` as a root certificate bundle file might
encounter connectivity issues.
== How To Test ==
Target behavior: OpenSSL initialization takes less time when the file
isn't present compared to it being there.
1. The following will create a symlink for testing after the change
has been integrated(i.e. the `.../tls/cert.pem` file is missing)
`ln -s /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem /etc/pki/tls/cert.pem`
2. Test the time of OpenSSL initialization or a package using it with
and without the aforementioned symlink.
(If there is no difference for package then it is most likely due to
OpenSSL not being configured to search for certs in default location)
== User Experience ==
Packages using a OpenSSL will have faster initialization time.
== Dependencies ==
Any package using `/etc/pki/tls/cert.pem` file are affected. It is
required that the maintainers change this so that user experience is
not compromised.
== Contingency Plan ==
* Contingency mechanism: We will postpone the change if majority or
critical package owners will be unable to make appropriate changes.
* Contingency deadline: before end of beta freeze(2025-02-18).
* Blocks release? The feature doesn't block release.
== Documentation ==
The change is documented as a part of ca-certificates package changelog.
== Release Notes ==
The /etc/pki/tls/cert.pem file has been deprecated
--
Aoife Moloney
Fedora Operations Architect
Fedora Project
Matrix: @amoloney:fedora.im
IRC: amoloney
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Subscribe to:
Posts (Atom)