-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEKl1CaPno2Qy4/AU8lFzKVeTWQe4FAmei9lcFAwAAAAAACgkQlFzKVeTWQe5f
VRAAoGLKEVOQjHNxQ5s0R5FMqVBiVk7CfMKq7sE5FDhCwRW3qnFBwbRunL78DtShIDYtmu9plriU
kvLE0P6nSygxediPin5G3rnsSlKiJ3ywY5yZgojcVI7dMuVvxohRxd7RBYuOlsqQOU7DVdIaJqsO
Sk05RlKsXZUr/D9ZSI6Nwb2kCInHFZu3S54hY+V5tWOTmtJlIMIcZFGrbgs6oPQNE3DmT8Qs0Mz/
0f1y9CE5KwkVOJC7mTGuwICOK9rj7vkm5M/by/gtt5OsxyZOaWauiXFq0LEiFcCSQ0PZbxutGgC0
EHk+HrnSudPOqhAWBCQJeqbSnAY4RTtW58QxL0XvGYKRqFWuXiDhJ2cKyZJJZdiNycZ0N39upTpr
NJBz14UDWseoLJBJn3tAZrikPtNjZ1qwYKobroIgDniDj/unaER1GQUSYPQuycP3VhmpVoCvA7iH
BKhT/nHFL1jVeTwWYxaIm15TO6oP7bGo4JmzGBjhIBKfIV0Sxo6nS6UurZ/P34uGDXVNQHVTTu5C
N+xZAMn6fNdZbMH9LjgDGFSj5Z/cFcmF1zUjXsgBLCq0pI9tFpCfcpYunXgKdG3jhbYTRSuktIFs
Vm5wkE4awaURk9hDk9VHL8lMvHLvlrwyRQIbaB+O6ai7orXScRekh9bCy1PNoBm0X8QYRHpSCXcU
RN0=
=Bswa
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7257-1
February 05, 2025
krb5 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
A system authentication measure could be bypassed.
Software Description:
- krb5: MIT Kerberos Network Authentication Protocol
Details:
Goldberg, Miro Haller, Nadia Heninger, Mike Milano, Dan Shumow, Marc
Stevens, and Adam Suhl discovered that Kerberos incorrectly authenticated
certain responses. An attacker able to intercept communications between a
RADIUS client and server could possibly use this issue to forge responses,
bypass authentication, and access network devices and services.
This update introduces support for the Message-Authenticator attribute in
non-EAP authentication methods for communications between Kerberos and a
RADIUS server.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libk5crypto3 1.21.3-3ubuntu0.1
libkrad0 1.21.3-3ubuntu0.1
Ubuntu 24.04 LTS
libk5crypto3 1.20.1-6ubuntu2.3
libkrad0 1.20.1-6ubuntu2.3
Ubuntu 22.04 LTS
libk5crypto3 1.19.2-2ubuntu0.5
libkrad0 1.19.2-2ubuntu0.5
Ubuntu 20.04 LTS
libk5crypto3 1.17-6ubuntu4.8
libkrad0 1.17-6ubuntu4.8
Ubuntu 18.04 LTS
libk5crypto3 1.16-2ubuntu0.4+esm3
Available with Ubuntu Pro
libkrad0 1.16-2ubuntu0.4+esm3
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libk5crypto3 1.13.2+dfsg-5ubuntu2.2+esm6
Available with Ubuntu Pro
libkrad0 1.13.2+dfsg-5ubuntu2.2+esm6
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libk5crypto3 1.12+dfsg-2ubuntu5.4+esm6
Available with Ubuntu Pro
libkrad0 1.12+dfsg-2ubuntu5.4+esm6
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7257-1
CVE-2024-3596
Package Information:
https://launchpad.net/ubuntu/+source/krb5/1.21.3-3ubuntu0.1
https://launchpad.net/ubuntu/+source/krb5/1.20.1-6ubuntu2.3
https://launchpad.net/ubuntu/+source/krb5/1.19.2-2ubuntu0.5
https://launchpad.net/ubuntu/+source/krb5/1.17-6ubuntu4.8
Tuesday, February 4, 2025
[USN-7234-3] Linux kernel (Azure) vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmeiODAFAwAAAAAACgkQZ0GeRcM5nt0/
OQgAhmfCcKIQD2q/yn34q1VBLRiyivURNM8UADh3dcFg/cIN/ekFEiMDfrGNglII4wt7Uy+1PclY
GgSftxYAvNY6yyDrUJ11+u9VArT77yNEqrTfXO19AXnkmUzQZ5rrZYIsnb0W9WqvqIC8N5Ur8DPe
bG0jlyqQSCtEhh+PDn2nKN5k0OWzuJGcQdquVJ8Qr6j/KzMdqympiaOJh5/0HzUta0BW6ToHMuo1
WuZ8wfZ7/x8Fd2ADAxFyQVeP1WQRFDVZUHgYnbsy/Dc8e32fovHGZwLhRmSsF/TuaZFCKyIcQ7FB
u09ZkFqBxl5u4y5IhCcQsQHS90/S1tJgbCZL7nVVtQ==
=kaN+
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7234-3
February 04, 2025
linux-azure, linux-azure-5.4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems
Details:
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2023-21400)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- TTY drivers;
- Netfilter;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53141, CVE-2024-53103, CVE-2024-40967, CVE-2024-53164)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.4.0-1143-azure 5.4.0-1143.150
linux-image-azure-lts-20.04 5.4.0.1143.137
Ubuntu 18.04 LTS
linux-image-5.4.0-1143-azure 5.4.0-1143.150~18.04.1
Available with Ubuntu Pro
linux-image-azure 5.4.0.1143.150~18.04.1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7234-3
https://ubuntu.com/security/notices/USN-7234-2
https://ubuntu.com/security/notices/USN-7234-1
CVE-2023-21400, CVE-2024-40967, CVE-2024-53103, CVE-2024-53141,
CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1143.150
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmeiODAFAwAAAAAACgkQZ0GeRcM5nt0/
OQgAhmfCcKIQD2q/yn34q1VBLRiyivURNM8UADh3dcFg/cIN/ekFEiMDfrGNglII4wt7Uy+1PclY
GgSftxYAvNY6yyDrUJ11+u9VArT77yNEqrTfXO19AXnkmUzQZ5rrZYIsnb0W9WqvqIC8N5Ur8DPe
bG0jlyqQSCtEhh+PDn2nKN5k0OWzuJGcQdquVJ8Qr6j/KzMdqympiaOJh5/0HzUta0BW6ToHMuo1
WuZ8wfZ7/x8Fd2ADAxFyQVeP1WQRFDVZUHgYnbsy/Dc8e32fovHGZwLhRmSsF/TuaZFCKyIcQ7FB
u09ZkFqBxl5u4y5IhCcQsQHS90/S1tJgbCZL7nVVtQ==
=kaN+
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7234-3
February 04, 2025
linux-azure, linux-azure-5.4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure: Linux kernel for Microsoft Azure Cloud systems
- linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems
Details:
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2023-21400)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- TTY drivers;
- Netfilter;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53141, CVE-2024-53103, CVE-2024-40967, CVE-2024-53164)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.4.0-1143-azure 5.4.0-1143.150
linux-image-azure-lts-20.04 5.4.0.1143.137
Ubuntu 18.04 LTS
linux-image-5.4.0-1143-azure 5.4.0-1143.150~18.04.1
Available with Ubuntu Pro
linux-image-azure 5.4.0.1143.150~18.04.1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7234-3
https://ubuntu.com/security/notices/USN-7234-2
https://ubuntu.com/security/notices/USN-7234-1
CVE-2023-21400, CVE-2024-40967, CVE-2024-53103, CVE-2024-53141,
CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1143.150
[USN-7238-3] Linux kernel (Low Latency) vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmeiOFIFAwAAAAAACgkQZ0GeRcM5nt0f
BAf+LAcRuiLTlI2XaNh6ReRdVafTcyK1aZ/lcMnQGyzwWdCnGzSWItJfOdBPlVCJ+DAvLdFXLAxJ
1yRpzws68qT5/JPQGsSeY+dMxEwcBEOm+GO5jKKZ5Yg7pExluZrP3ICzeyNXG2+ToW4l70W/76uJ
LaqG0qgCzpezp6kTlafOUkwng+CXU4Zlnm0K524xYL5EONDKKmNhK7QybrhcwFrqxVLoxhUnYxYL
QCTZG5EO0dRMFXYk6PJWLY/W6NerL7NcClbQoDKtQJnZwpbHTnFHIdkAl+s28oi1CBG4Y9IW7QuI
2YJyPSeFA1eDLaah0owXuW6efEbOnxdHUc7FqhyZvQ==
=1G96
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7238-3
February 04, 2025
linux-lowlatency vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-lowlatency: Linux low latency kernel
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53103, CVE-2024-53164)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
linux-image-6.11.0-1008-lowlatency 6.11.0-1008.8
linux-image-6.11.0-1008-lowlatency-64k 6.11.0-1008.8
linux-image-lowlatency 6.11.0-1008.8
linux-image-lowlatency-64k 6.11.0-1008.8
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7238-3
https://ubuntu.com/security/notices/USN-7238-2
https://ubuntu.com/security/notices/USN-7238-1
CVE-2024-53103, CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-lowlatency/6.11.0-1008.8
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmeiOFIFAwAAAAAACgkQZ0GeRcM5nt0f
BAf+LAcRuiLTlI2XaNh6ReRdVafTcyK1aZ/lcMnQGyzwWdCnGzSWItJfOdBPlVCJ+DAvLdFXLAxJ
1yRpzws68qT5/JPQGsSeY+dMxEwcBEOm+GO5jKKZ5Yg7pExluZrP3ICzeyNXG2+ToW4l70W/76uJ
LaqG0qgCzpezp6kTlafOUkwng+CXU4Zlnm0K524xYL5EONDKKmNhK7QybrhcwFrqxVLoxhUnYxYL
QCTZG5EO0dRMFXYk6PJWLY/W6NerL7NcClbQoDKtQJnZwpbHTnFHIdkAl+s28oi1CBG4Y9IW7QuI
2YJyPSeFA1eDLaah0owXuW6efEbOnxdHUc7FqhyZvQ==
=1G96
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7238-3
February 04, 2025
linux-lowlatency vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-lowlatency: Linux low latency kernel
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53103, CVE-2024-53164)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
linux-image-6.11.0-1008-lowlatency 6.11.0-1008.8
linux-image-6.11.0-1008-lowlatency-64k 6.11.0-1008.8
linux-image-lowlatency 6.11.0-1008.8
linux-image-lowlatency-64k 6.11.0-1008.8
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7238-3
https://ubuntu.com/security/notices/USN-7238-2
https://ubuntu.com/security/notices/USN-7238-1
CVE-2024-53103, CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-lowlatency/6.11.0-1008.8
[USN-7247-1] OpenCV vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEyMDHOTG0YH5UsajI8pSCVQZYHygFAmeiIycFAwAAAAAACgkQ8pSCVQZYHyhH
/w//WD2vcJP63z+OtlU06SphYF7hQ34M0DIi1MKXdLTYTkqgljSk3VRuezmzi8N/7WVI5l749uvm
Scib5B7jEFK9Dv36kWaVKY058t96bZNmtgFczPtprwowKqbApyfUQxK37BvRofojvbBRry2a/JSm
YKAGVKdfjhxXZpH7ursJa0RZN1bLh6xUJiOmCpMf0902NLKU1k78OSPHG22cMXt20cCXI5yjjmS3
Sy35RZ9RjuO8Nd84ab3ny+j+Vd1ddUKlmBX5AdrNRvCGLzBktkV4m9H356pD5Dq8lC64icvN0qwG
EjLHaaQu2y5rUTqgWTLOSiMnKL1a7zilS1+LML0UMhIvYykOoxZ5mk7bXfWa9GD14VnOQKnEXYRm
/bMEviW5uJ/lLKkbKbyMWBWuePDvwGrX1GpCJarLC3ea2YH95lbaH5HVqMYEOGOJGfAqv8Oy8TYA
ZprLWd0vve3XhBWpTGuIeLU0k/UwOqEuURCDiZXGYOQXjGWneFhpfLM8CWW4bxI+EgczvoZU0JpB
M9B5KV+bQibyIbmolTVsy868PGqWavpqQqA7IcaGKmvFDxAOr7i9ZOoHTRT3VGmtHoSo3FmZNpoF
6PPnulJsSQLQsh3ZQWkXxb2HDOhvji9OjsidyP2jFilfJApR1Nw/+N0Myj70GuZHPCSbc5uzEdaN
TBg=
=cnBp
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7247-1
February 03, 2025
opencv vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in OpenCV.
Software Description:
- opencv: computer vision library
Details:
It was discovered that OpenCV did not properly manage certain XML data,
leading to a NULL pointer dereference. If a user were tricked into
loading a specially crafted file, a remote attacker could possibly use
this issue to make OpenCV crash, resulting in a denial of service.
This issue only affected Ubuntu 18.04 LTS. (CVE-2019-14493)
It was discovered that OpenCV may perform out-of-bounds reads in certain
situations. An attacker could possibly use this issue to cause OpenCV to
crash, resulting in a denial of service, or the execution of arbitrary
code. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-16249, CVE-2019-19624)
It was discovered that the QR code module of OpenCV incorrectly processed
certain maliciously crafted QR codes. A remote attacker could possibly use
this issue to cause OpenCV to crash, resulting in a denial of service.
This issue only affected Ubuntu 22.04 LTS. (CVE-2023-2617, CVE-2023-2618)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
libopencv-contrib4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-core4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-dev 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-dnn4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-flann4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-imgcodecs4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-objdetect4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
opencv-data 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
libopencv-core3.2 3.2.0+dfsg-4ubuntu0.1+esm4
Available with Ubuntu Pro
libopencv-dev 3.2.0+dfsg-4ubuntu0.1+esm4
Available with Ubuntu Pro
opencv-data 3.2.0+dfsg-4ubuntu0.1+esm4
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7247-1
CVE-2019-14493, CVE-2019-16249, CVE-2019-19624, CVE-2023-2617,
CVE-2023-2618
wsF5BAABCAAjFiEEyMDHOTG0YH5UsajI8pSCVQZYHygFAmeiIycFAwAAAAAACgkQ8pSCVQZYHyhH
/w//WD2vcJP63z+OtlU06SphYF7hQ34M0DIi1MKXdLTYTkqgljSk3VRuezmzi8N/7WVI5l749uvm
Scib5B7jEFK9Dv36kWaVKY058t96bZNmtgFczPtprwowKqbApyfUQxK37BvRofojvbBRry2a/JSm
YKAGVKdfjhxXZpH7ursJa0RZN1bLh6xUJiOmCpMf0902NLKU1k78OSPHG22cMXt20cCXI5yjjmS3
Sy35RZ9RjuO8Nd84ab3ny+j+Vd1ddUKlmBX5AdrNRvCGLzBktkV4m9H356pD5Dq8lC64icvN0qwG
EjLHaaQu2y5rUTqgWTLOSiMnKL1a7zilS1+LML0UMhIvYykOoxZ5mk7bXfWa9GD14VnOQKnEXYRm
/bMEviW5uJ/lLKkbKbyMWBWuePDvwGrX1GpCJarLC3ea2YH95lbaH5HVqMYEOGOJGfAqv8Oy8TYA
ZprLWd0vve3XhBWpTGuIeLU0k/UwOqEuURCDiZXGYOQXjGWneFhpfLM8CWW4bxI+EgczvoZU0JpB
M9B5KV+bQibyIbmolTVsy868PGqWavpqQqA7IcaGKmvFDxAOr7i9ZOoHTRT3VGmtHoSo3FmZNpoF
6PPnulJsSQLQsh3ZQWkXxb2HDOhvji9OjsidyP2jFilfJApR1Nw/+N0Myj70GuZHPCSbc5uzEdaN
TBg=
=cnBp
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7247-1
February 03, 2025
opencv vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in OpenCV.
Software Description:
- opencv: computer vision library
Details:
It was discovered that OpenCV did not properly manage certain XML data,
leading to a NULL pointer dereference. If a user were tricked into
loading a specially crafted file, a remote attacker could possibly use
this issue to make OpenCV crash, resulting in a denial of service.
This issue only affected Ubuntu 18.04 LTS. (CVE-2019-14493)
It was discovered that OpenCV may perform out-of-bounds reads in certain
situations. An attacker could possibly use this issue to cause OpenCV to
crash, resulting in a denial of service, or the execution of arbitrary
code. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-16249, CVE-2019-19624)
It was discovered that the QR code module of OpenCV incorrectly processed
certain maliciously crafted QR codes. A remote attacker could possibly use
this issue to cause OpenCV to crash, resulting in a denial of service.
This issue only affected Ubuntu 22.04 LTS. (CVE-2023-2617, CVE-2023-2618)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
libopencv-contrib4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-core4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-dev 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-dnn4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-flann4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-imgcodecs4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
libopencv-objdetect4.5d 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
opencv-data 4.5.4+dfsg-9ubuntu4+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
libopencv-core3.2 3.2.0+dfsg-4ubuntu0.1+esm4
Available with Ubuntu Pro
libopencv-dev 3.2.0+dfsg-4ubuntu0.1+esm4
Available with Ubuntu Pro
opencv-data 3.2.0+dfsg-4ubuntu0.1+esm4
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7247-1
CVE-2019-14493, CVE-2019-16249, CVE-2019-19624, CVE-2023-2617,
CVE-2023-2618
[USN-7249-1] libvpx vulnerability
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEyMDHOTG0YH5UsajI8pSCVQZYHygFAmeiIu0FAwAAAAAACgkQ8pSCVQZYHyjf
PQ//fg/aniZsGSsfx9cppPtjqU3EfoE49qWTrTMScUz9a0pkVyWQkbWipfqxwT7ExpaXAjM+U+uW
BlRSb4ymNKH1PDSphjDXkTdZ6U12emzAxcblu2XE4+sOijuBEXVKrnSLsZ43Oy9aDMCprflmQqre
dd5VSJnJ8T+40IToZ/z0JjWdNZN/7QkxplBnjPBymPYC0RZQn6KrCT+1UfDqbX39xi4UTENlwmP6
YQJY7XbxfzcNSuYQJs2FgJDTbkFZgF2qIMGuXg2LzCbvJboqbaY4G7w/8JRaKjN7z8hieUE6hDwl
rYf+6dL7VxFEoe2kVDI5gQ9tCxfFBOJnpo6kbQf0l3OTpcrDC0JrLMcWLvnUO3bWudXc1770sqcs
ZNYqzDuVGr+XBDAePwyYbpN9Rqp2D0XDvpdp+mT7cKXt++yKktx9yoC/bm+4Bz8f67bJoPGQA6/w
ijvSBoz+H2FNurg7KNUoUBWjf4hpV/KwKNGtIjk/OtkorLT1kEjWNuznCo//oyCg/SbY+8E40/f7
CRoZEmktNx41bbRC686LLOHudkZa3SRhArAMLVHuafoIy3kmikbmOHFcAqQzSXwZ19aDiEX/GoUa
0FIp/4EbsK/RBkvin7t/nscNA0UGqnmzE7l42ZkWu2jXw2q3nbwgv03geDixjxW02ar0UEqHuJTL
My0=
=CYav
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7249-1
February 03, 2025
libvpx vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
libvpx could be made to crash or run programs as your login if it
opened a specially crafted image file.
Software Description:
- libvpx: VP8 and VP9 video codec
Details:
Xiantong Hou discovered that libvpx would overflow when attempting to
allocate memory for very large images. If an application using libvpx
opened a specially crafted file, a remote attacker could possibly use
this issue to cause the application to crash, resulting in a denial
of service, or the execution of arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
libvpx5 1.7.0-3ubuntu0.18.04.1+esm2
Available with Ubuntu Pro
vpx-tools 1.7.0-3ubuntu0.18.04.1+esm2
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libvpx3 1.5.0-2ubuntu1.1+esm3
Available with Ubuntu Pro
vpx-tools 1.5.0-2ubuntu1.1+esm3
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libvpx1 1.3.0-2ubuntu0.1+esm3
Available with Ubuntu Pro
vpx-tools 1.3.0-2ubuntu0.1+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-7249-1
CVE-2024-5197
wsF5BAABCAAjFiEEyMDHOTG0YH5UsajI8pSCVQZYHygFAmeiIu0FAwAAAAAACgkQ8pSCVQZYHyjf
PQ//fg/aniZsGSsfx9cppPtjqU3EfoE49qWTrTMScUz9a0pkVyWQkbWipfqxwT7ExpaXAjM+U+uW
BlRSb4ymNKH1PDSphjDXkTdZ6U12emzAxcblu2XE4+sOijuBEXVKrnSLsZ43Oy9aDMCprflmQqre
dd5VSJnJ8T+40IToZ/z0JjWdNZN/7QkxplBnjPBymPYC0RZQn6KrCT+1UfDqbX39xi4UTENlwmP6
YQJY7XbxfzcNSuYQJs2FgJDTbkFZgF2qIMGuXg2LzCbvJboqbaY4G7w/8JRaKjN7z8hieUE6hDwl
rYf+6dL7VxFEoe2kVDI5gQ9tCxfFBOJnpo6kbQf0l3OTpcrDC0JrLMcWLvnUO3bWudXc1770sqcs
ZNYqzDuVGr+XBDAePwyYbpN9Rqp2D0XDvpdp+mT7cKXt++yKktx9yoC/bm+4Bz8f67bJoPGQA6/w
ijvSBoz+H2FNurg7KNUoUBWjf4hpV/KwKNGtIjk/OtkorLT1kEjWNuznCo//oyCg/SbY+8E40/f7
CRoZEmktNx41bbRC686LLOHudkZa3SRhArAMLVHuafoIy3kmikbmOHFcAqQzSXwZ19aDiEX/GoUa
0FIp/4EbsK/RBkvin7t/nscNA0UGqnmzE7l42ZkWu2jXw2q3nbwgv03geDixjxW02ar0UEqHuJTL
My0=
=CYav
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7249-1
February 03, 2025
libvpx vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
libvpx could be made to crash or run programs as your login if it
opened a specially crafted image file.
Software Description:
- libvpx: VP8 and VP9 video codec
Details:
Xiantong Hou discovered that libvpx would overflow when attempting to
allocate memory for very large images. If an application using libvpx
opened a specially crafted file, a remote attacker could possibly use
this issue to cause the application to crash, resulting in a denial
of service, or the execution of arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
libvpx5 1.7.0-3ubuntu0.18.04.1+esm2
Available with Ubuntu Pro
vpx-tools 1.7.0-3ubuntu0.18.04.1+esm2
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libvpx3 1.5.0-2ubuntu1.1+esm3
Available with Ubuntu Pro
vpx-tools 1.5.0-2ubuntu1.1+esm3
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libvpx1 1.3.0-2ubuntu0.1+esm3
Available with Ubuntu Pro
vpx-tools 1.3.0-2ubuntu0.1+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-7249-1
CVE-2024-5197
[USN-7248-1] libndp vulnerability
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEyMDHOTG0YH5UsajI8pSCVQZYHygFAmeiIJ0FAwAAAAAACgkQ8pSCVQZYHygr
hw//TLglRGarSfF5xSKvzCak+ieFH5GgOM/LNme2t8A76jsiorghP4DSimm9Ampui37+9KmJfyxl
1gfJewOdmGvvudrNVNC2KQRkUILeAZEJpWMJVkmV0v7N7LvG02ci09/8qtu942SkTKPFxbOiB+xs
XWHOgNDCP0wYpZdaPtnigehTkrSKjrd1oM6M5Ew6Z6LISGiydL/rd9foR4MFX6vcKa0QyrsaLDlF
uQW1yyCReXHjSWSEjVc5b98ppegCm7iubgxF3mc6hbJ5W1hsOCqJ7gRnQehrdxx7Gz0vvl8NjFV+
0WbbYp60xPhdhUF6lJVR7cwhuTdjrlz1ZSBERwMdqmw38A5+C1Y5dyNFCXqk8fnIUhw8gPPMgcL/
ILP5yIuNkGYD/LKNygWPZ0VsxMLQUw8ewLbogq1LMWn5d5f98UiR2t8OWmyqD5tV0c+htUJAChqH
+SI886ebbmmLzD4AUPmusb+H5f/9X15FhptObhU38lI1vQR0+X0XfosaLgg7nbGrQ8U1tv0hSHN3
K4MfX3617Q4iFvbDsr8gnz62UaHEbpstbuhxPhLnXjPwPOrjloqfo0XJJ4Xoolso0SfKyS/yRPzp
ccZitMAwchW8mNOM69V6hN6hKEKy9TXS7SfGcG/wxgQW2wQ8Z2DkEoE0g/t2n5bPsitqspqneIq5
GVY=
=vXUu
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7248-1
February 03, 2025
libndp vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
libndp could be made to crash or run programs if it received specially
crafted network traffic.
Software Description:
- libndp: Library for Neighbor Discovery Protocol
Details:
It was discovered that libndp incorrectly handled certain malformed IPv6
router advertisement packets. A local attacker could possibly use this
issue to cause NetworkManager to crash, resulting in a denial of service,
or the execution of arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
libndp0 1.6-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libndp0 1.4-2ubuntu0.16.04.1+esm1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7248-1
CVE-2024-5564
wsF5BAABCAAjFiEEyMDHOTG0YH5UsajI8pSCVQZYHygFAmeiIJ0FAwAAAAAACgkQ8pSCVQZYHygr
hw//TLglRGarSfF5xSKvzCak+ieFH5GgOM/LNme2t8A76jsiorghP4DSimm9Ampui37+9KmJfyxl
1gfJewOdmGvvudrNVNC2KQRkUILeAZEJpWMJVkmV0v7N7LvG02ci09/8qtu942SkTKPFxbOiB+xs
XWHOgNDCP0wYpZdaPtnigehTkrSKjrd1oM6M5Ew6Z6LISGiydL/rd9foR4MFX6vcKa0QyrsaLDlF
uQW1yyCReXHjSWSEjVc5b98ppegCm7iubgxF3mc6hbJ5W1hsOCqJ7gRnQehrdxx7Gz0vvl8NjFV+
0WbbYp60xPhdhUF6lJVR7cwhuTdjrlz1ZSBERwMdqmw38A5+C1Y5dyNFCXqk8fnIUhw8gPPMgcL/
ILP5yIuNkGYD/LKNygWPZ0VsxMLQUw8ewLbogq1LMWn5d5f98UiR2t8OWmyqD5tV0c+htUJAChqH
+SI886ebbmmLzD4AUPmusb+H5f/9X15FhptObhU38lI1vQR0+X0XfosaLgg7nbGrQ8U1tv0hSHN3
K4MfX3617Q4iFvbDsr8gnz62UaHEbpstbuhxPhLnXjPwPOrjloqfo0XJJ4Xoolso0SfKyS/yRPzp
ccZitMAwchW8mNOM69V6hN6hKEKy9TXS7SfGcG/wxgQW2wQ8Z2DkEoE0g/t2n5bPsitqspqneIq5
GVY=
=vXUu
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7248-1
February 03, 2025
libndp vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
libndp could be made to crash or run programs if it received specially
crafted network traffic.
Software Description:
- libndp: Library for Neighbor Discovery Protocol
Details:
It was discovered that libndp incorrectly handled certain malformed IPv6
router advertisement packets. A local attacker could possibly use this
issue to cause NetworkManager to crash, resulting in a denial of service,
or the execution of arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
libndp0 1.6-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libndp0 1.4-2ubuntu0.16.04.1+esm1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7248-1
CVE-2024-5564
Monday, February 3, 2025
[USN-7251-1] HarfBuzz vulnerability
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmeg6+EFAwAAAAAACgkQZWnYVadEvpOs
LRAAkunQYOmfMGffp8fzMEGFr7eS+y4orZviM3/b0Y1dflOWX1XewetToFnkvKePWOu/ON1cW8EI
OSXQvqibJ45c9cEW9/hdRCQTdsJ4r2Cak+vicSZTR+bg2QxNFc3NyvjWfezECQSHuSAmav36RcIh
VSq+q497uv59oLePF5RKexxnnNleWdr5NwZLS5YEy/TNmtidU6KKWGFtHxcPSq/JuvDtAFIW5yP4
aHtEKkxL0YBTggpg2oG75IdiUFai7Ga+HpdmiPoOp2GAmOk5mjvOdDNXWGhwzhZgzzqYheeXyrmz
Myh3EU7fT04XacBF8ZSY//8JIvq6Pl9hQTRiOjNu2hzCQqKUgLEgqBP35OuAWRlVwP57H8NTWROA
50GqHA8P2Z0ZA7VlmrQjt2cAmdART4AOgQ4WJ6jbvyaVwHyhFqRJRVE5Dv/RoWt9Rle7S0sZwjDP
rkHwktbcU0Ckt4h25BbYbBlYJBqtpgrU3VKo3vKRoK3kBM3nXjXLWawoj6Og1J3qvK3W11BzE03h
XSsYWYj2vZYLB785RFiTBhXui81tt8+VoVkUeHOTTMvztPtZrT13lxkQ3rNQ5tdxAebZcn0MxlMr
Ep+RFv7LWYygHT1BdovTjSx6hTNDDBRV6svrGVBtLmdex86sJtkK78L3Gpscfc9hbesA4XSzVbSr
dnY=
=1oKa
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7251-1
February 03, 2025
harfbuzz vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
HarfBuzz could be made to consume resources if it opened a specially
crafted font.
Software Description:
- harfbuzz: OpenType text shaping engine
Details:
It was discovered that HarfBuzz incorrectly handled shaping certain fonts.
A remote attacker could possibly use this issue to cause HarfBuzz to
consume resources, leading to a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
libharfbuzz0b 2.7.4-1ubuntu3.2
Ubuntu 20.04 LTS
libharfbuzz0b 2.6.4-1ubuntu4.3
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7251-1
CVE-2023-25193
Package Information:
https://launchpad.net/ubuntu/+source/harfbuzz/2.7.4-1ubuntu3.2
https://launchpad.net/ubuntu/+source/harfbuzz/2.6.4-1ubuntu4.3
wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmeg6+EFAwAAAAAACgkQZWnYVadEvpOs
LRAAkunQYOmfMGffp8fzMEGFr7eS+y4orZviM3/b0Y1dflOWX1XewetToFnkvKePWOu/ON1cW8EI
OSXQvqibJ45c9cEW9/hdRCQTdsJ4r2Cak+vicSZTR+bg2QxNFc3NyvjWfezECQSHuSAmav36RcIh
VSq+q497uv59oLePF5RKexxnnNleWdr5NwZLS5YEy/TNmtidU6KKWGFtHxcPSq/JuvDtAFIW5yP4
aHtEKkxL0YBTggpg2oG75IdiUFai7Ga+HpdmiPoOp2GAmOk5mjvOdDNXWGhwzhZgzzqYheeXyrmz
Myh3EU7fT04XacBF8ZSY//8JIvq6Pl9hQTRiOjNu2hzCQqKUgLEgqBP35OuAWRlVwP57H8NTWROA
50GqHA8P2Z0ZA7VlmrQjt2cAmdART4AOgQ4WJ6jbvyaVwHyhFqRJRVE5Dv/RoWt9Rle7S0sZwjDP
rkHwktbcU0Ckt4h25BbYbBlYJBqtpgrU3VKo3vKRoK3kBM3nXjXLWawoj6Og1J3qvK3W11BzE03h
XSsYWYj2vZYLB785RFiTBhXui81tt8+VoVkUeHOTTMvztPtZrT13lxkQ3rNQ5tdxAebZcn0MxlMr
Ep+RFv7LWYygHT1BdovTjSx6hTNDDBRV6svrGVBtLmdex86sJtkK78L3Gpscfc9hbesA4XSzVbSr
dnY=
=1oKa
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7251-1
February 03, 2025
harfbuzz vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
HarfBuzz could be made to consume resources if it opened a specially
crafted font.
Software Description:
- harfbuzz: OpenType text shaping engine
Details:
It was discovered that HarfBuzz incorrectly handled shaping certain fonts.
A remote attacker could possibly use this issue to cause HarfBuzz to
consume resources, leading to a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
libharfbuzz0b 2.7.4-1ubuntu3.2
Ubuntu 20.04 LTS
libharfbuzz0b 2.6.4-1ubuntu4.3
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7251-1
CVE-2023-25193
Package Information:
https://launchpad.net/ubuntu/+source/harfbuzz/2.7.4-1ubuntu3.2
https://launchpad.net/ubuntu/+source/harfbuzz/2.6.4-1ubuntu4.3
[USN-7233-3] Linux kernel (Azure) vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmeg01wFAwAAAAAACgkQZ0GeRcM5nt0Y
Xgf+PrhJ7BoUuHQUX8ZzfcRnudoGCv/W+6cajwCQyKoxSqrqMwnKnrn09PpHsL3Zh7WsEGvdxBzl
gXKigVGP/0FyXWaBZkCSjGNoC9mQM/BQaGrk4HeTJndCVEUvZunHG/pxb0ihTBSjN/ypiq9DC8Pu
Iqhu4LC6v7YRw7ceP4JeLGU32FrZnrOMrE+X//YrN0iOnrskEXpjmHM9MPPWaD9uXUzCa+twK+bf
Jw6uqlWzvXTQBxDNdK5dx7T88ovPcf2FZMFwP1PO0uKylIFyTCLlbwlBxMzm3q9o7CT3TIep6DZ2
y5Sq45GfXlOABgKP5Lb2inPKDyJGfzYPE7Ey/RNf8A==
=G6V8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7233-3
February 03, 2025
linux-azure vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-meta-azure: Complete Linux kernel for Azure systems.
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Multiple devices driver;
- Network drivers;
- Mellanox network drivers;
- S/390 drivers;
- SCSI subsystem;
- Sonic Silicon Backplane drivers;
- File systems infrastructure;
- Closures library;
- Netfilter;
- TIPC protocol;
- VMware vSockets driver;
(CVE-2024-26929, CVE-2024-40982, CVE-2024-42311, CVE-2024-53141,
CVE-2024-41066, CVE-2024-38661, CVE-2024-38553, CVE-2024-43914,
CVE-2024-26663, CVE-2024-42252, CVE-2024-38597, CVE-2024-53103,
CVE-2024-41020, CVE-2024-41012, CVE-2024-26595)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS
linux-image-4.15.0-1185-azure 4.15.0-1185.200~16.04.1
Available with Ubuntu Pro
linux-image-azure 4.15.0.1185.200~16.04.1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7233-3
https://ubuntu.com/security/notices/USN-7233-2
https://ubuntu.com/security/notices/USN-7233-1
CVE-2024-26595, CVE-2024-26663, CVE-2024-26929, CVE-2024-38553,
CVE-2024-38597, CVE-2024-38661, CVE-2024-40982, CVE-2024-41012,
CVE-2024-41020, CVE-2024-41066, CVE-2024-42252, CVE-2024-42311,
CVE-2024-43914, CVE-2024-53103, CVE-2024-53141
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmeg01wFAwAAAAAACgkQZ0GeRcM5nt0Y
Xgf+PrhJ7BoUuHQUX8ZzfcRnudoGCv/W+6cajwCQyKoxSqrqMwnKnrn09PpHsL3Zh7WsEGvdxBzl
gXKigVGP/0FyXWaBZkCSjGNoC9mQM/BQaGrk4HeTJndCVEUvZunHG/pxb0ihTBSjN/ypiq9DC8Pu
Iqhu4LC6v7YRw7ceP4JeLGU32FrZnrOMrE+X//YrN0iOnrskEXpjmHM9MPPWaD9uXUzCa+twK+bf
Jw6uqlWzvXTQBxDNdK5dx7T88ovPcf2FZMFwP1PO0uKylIFyTCLlbwlBxMzm3q9o7CT3TIep6DZ2
y5Sq45GfXlOABgKP5Lb2inPKDyJGfzYPE7Ey/RNf8A==
=G6V8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7233-3
February 03, 2025
linux-azure vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-meta-azure: Complete Linux kernel for Azure systems.
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Multiple devices driver;
- Network drivers;
- Mellanox network drivers;
- S/390 drivers;
- SCSI subsystem;
- Sonic Silicon Backplane drivers;
- File systems infrastructure;
- Closures library;
- Netfilter;
- TIPC protocol;
- VMware vSockets driver;
(CVE-2024-26929, CVE-2024-40982, CVE-2024-42311, CVE-2024-53141,
CVE-2024-41066, CVE-2024-38661, CVE-2024-38553, CVE-2024-43914,
CVE-2024-26663, CVE-2024-42252, CVE-2024-38597, CVE-2024-53103,
CVE-2024-41020, CVE-2024-41012, CVE-2024-26595)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS
linux-image-4.15.0-1185-azure 4.15.0-1185.200~16.04.1
Available with Ubuntu Pro
linux-image-azure 4.15.0.1185.200~16.04.1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7233-3
https://ubuntu.com/security/notices/USN-7233-2
https://ubuntu.com/security/notices/USN-7233-1
CVE-2024-26595, CVE-2024-26663, CVE-2024-26929, CVE-2024-38553,
CVE-2024-38597, CVE-2024-38661, CVE-2024-40982, CVE-2024-41012,
CVE-2024-41020, CVE-2024-41066, CVE-2024-42252, CVE-2024-42311,
CVE-2024-43914, CVE-2024-53103, CVE-2024-53141
[arch-announce] Glibc 2.41 corrupting Discord installation
We plan to move `glibc` and its friends to stable later today, Feb 3. After installing the update, the Discord client will show a red warning that the installation is corrupt.
This issue has been fixed in the Discord canary build. If you rely on audio connectivity, please use the canary build, login via browser or the flatpak version until the fix hits the stable Discord release.
There have been no reports that (written) chat connectivity is affected.
URL: https://archlinux.org/news/glibc-241-corrupting-discord-installation/
This issue has been fixed in the Discord canary build. If you rely on audio connectivity, please use the canary build, login via browser or the flatpak version until the fix hits the stable Discord release.
There have been no reports that (written) chat connectivity is affected.
URL: https://archlinux.org/news/glibc-241-corrupting-discord-installation/
github2fedmsg and fedmsg EOL date changed to 13th February
Hello everyone,
Fedora CoreOS team reached to us to postpone the date of decommissioning
github2fedmsg and fedmsg in Fedora Infrastructure as they still need
some time to migrate.
I will still start working on this in our staging environment, but in
production the new date is 13th February.
On behalf of Fedora Infrastructure team,
Michal 'Zlopez'
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Fedora CoreOS team reached to us to postpone the date of decommissioning
github2fedmsg and fedmsg in Fedora Infrastructure as they still need
some time to migrate.
I will still start working on this in our staging environment, but in
production the new date is 13th February.
On behalf of Fedora Infrastructure team,
Michal 'Zlopez'
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Fedora Linux 42 Mass Branching will be held Tomorrow
Hi All,
Fedora Linux 42 is going to be branched tomorrow as per the experience
of the previous release, we are going to disable the new koji builds
for the duration of this event. For more on this please refer to the
past discussion[1] In Fedora 41, we tried a new approach to block external
submissions in koji by setting custom restrictions, we will try to use the
same method again this time.
All builds that will be running at that time for the rawhide will be
canceled and can be resubmitted by maintainers after the branching.
All rawhide updates that are pending for rawhide will be unpushed.
Once Fedora Linux 42 is branched we will reenable builds in Koji with
a notification to this list. For any queries, we are on
#releng:fedoraproject.org and Fedora Mass Branching Release
Tracker[2].
Samyak Jain,
Fedora Release Engineering
[1] https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/GWY4TIDIP65HA2V33F2ROU2MJLKMRZ7E/#GWY4TIDIP65HA2V33F2ROU2MJLKMRZ7E
[2] https://pagure.io/releng/issue/12550
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Fedora Linux 42 is going to be branched tomorrow as per the experience
of the previous release, we are going to disable the new koji builds
for the duration of this event. For more on this please refer to the
past discussion[1] In Fedora 41, we tried a new approach to block external
submissions in koji by setting custom restrictions, we will try to use the
same method again this time.
All builds that will be running at that time for the rawhide will be
canceled and can be resubmitted by maintainers after the branching.
All rawhide updates that are pending for rawhide will be unpushed.
Once Fedora Linux 42 is branched we will reenable builds in Koji with
a notification to this list. For any queries, we are on
#releng:fedoraproject.org and Fedora Mass Branching Release
Tracker[2].
Samyak Jain,
Fedora Release Engineering
[1] https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/GWY4TIDIP65HA2V33F2ROU2MJLKMRZ7E/#GWY4TIDIP65HA2V33F2ROU2MJLKMRZ7E
[2] https://pagure.io/releng/issue/12550
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
[USN-7250-1] Netdata vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmegYjMFAwAAAAAACgkQuGrtzot7pOeF
mgwAneCHSrFgAcq/pHfzWcjIuN8jH4V7oq08pbcC7Qt/je288hA3xwxJRi69VAtYmGvu+/bOmCFD
VJUc8aPsJ63xdTP2+uolS61kVK12okWNRilqKg9bxBOnXMuKG2gPMSzsrCJzqrCbWb1t3PN8r4ve
TmgiPJGxi9guq4ZXuf+gP9JC0z8a436ENK91+FsiDXjFLBpNtzJaNwogZc/koTQzOkwAodXvaMlx
iEjtJFKSrvQtxASmuO99s1HQC2H6i7/lY+DFUrRxHq63G9dr5/MAu4ers4jQdmc7jnZlV2a15Bgu
DPnHlmTHkmZB4uIqcGYmVY05qlu7c7HJqBq8rsWdxdkj7k/NH38dXNWTjkK29OPeriyLpHjSEm22
nKlfFiQOySBTHI51QgLj/yVp3XgVRJkx2KtEhQdYJrgdyDMJLi0gQviGA11LSpfCHelCqAObISK0
E48zUpPT8dTIBR64xzrN+i/6yyvqnIlQYgl9+ORmJQ0eXAkPmrtMmJKdRH0a
=kSaI
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7250-1
February 03, 2025
netdata vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in netdata.
Software Description:
- netdata: real-time performance monitoring
Details:
It was discovered that Netdata incorrectly handled parsing JSON input,
which could lead to a JSON injection. An attacker could possibly use
this issue to execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-18836)
It was discovered that Netdata incorrectly handled parsing HTTP headers,
which could lead to a HTTP header injection. An attacker could possibly
use this issue to cause a denial of service or leak sensitive information.
This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18837)
It was discovered that Netdata incorrectly handled parsing URLs, which
could lead to a log injection. An attacker could possibly use this issue
to consume system resources, resulting in a denial of service. This issue
only affected Ubuntu 18.04 LTS. (CVE-2018-18838)
It was discovered Netdata improperly authenticated API keys. An attacker
could possibly use this issue to leak sensitive information or execute
arbitrary code. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2023-22497)
It was discovered Fluent Bit, vendored in Netdata, incorrectly handled
parsing HTTP payloads. An attacker could possibly use this issue to
disrupt logging. This issue only affected Ubuntu 24.10. (CVE-2024-23722)
It was discovered that WebAssembly Micro Runtime, vendored in Netdata,
incorrectly handled memory. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.10.
(CVE-2024-34250, CVE-2024-34251)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
netdata-core 1.44.3-2ubuntu0.1
netdata-plugins-bash 1.44.3-2ubuntu0.1
netdata-web 1.44.3-2ubuntu0.1
Ubuntu 22.04 LTS
netdata-core 1.33.1-1ubuntu1+esm1
Available with Ubuntu Pro
netdata-plugins-bash 1.33.1-1ubuntu1+esm1
Available with Ubuntu Pro
netdata-web 1.33.1-1ubuntu1+esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
netdata-core 1.19.0-3ubuntu1+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
netdata 1.9.0+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
netdata-data 1.9.0+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
After a standard system update you need to restart Netdata to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7250-1
CVE-2018-18836, CVE-2018-18837, CVE-2018-18838, CVE-2023-22497,
CVE-2024-23722, CVE-2024-34250, CVE-2024-34251
Package Information:
https://launchpad.net/ubuntu/+source/netdata/1.44.3-2ubuntu0.1
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmegYjMFAwAAAAAACgkQuGrtzot7pOeF
mgwAneCHSrFgAcq/pHfzWcjIuN8jH4V7oq08pbcC7Qt/je288hA3xwxJRi69VAtYmGvu+/bOmCFD
VJUc8aPsJ63xdTP2+uolS61kVK12okWNRilqKg9bxBOnXMuKG2gPMSzsrCJzqrCbWb1t3PN8r4ve
TmgiPJGxi9guq4ZXuf+gP9JC0z8a436ENK91+FsiDXjFLBpNtzJaNwogZc/koTQzOkwAodXvaMlx
iEjtJFKSrvQtxASmuO99s1HQC2H6i7/lY+DFUrRxHq63G9dr5/MAu4ers4jQdmc7jnZlV2a15Bgu
DPnHlmTHkmZB4uIqcGYmVY05qlu7c7HJqBq8rsWdxdkj7k/NH38dXNWTjkK29OPeriyLpHjSEm22
nKlfFiQOySBTHI51QgLj/yVp3XgVRJkx2KtEhQdYJrgdyDMJLi0gQviGA11LSpfCHelCqAObISK0
E48zUpPT8dTIBR64xzrN+i/6yyvqnIlQYgl9+ORmJQ0eXAkPmrtMmJKdRH0a
=kSaI
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7250-1
February 03, 2025
netdata vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in netdata.
Software Description:
- netdata: real-time performance monitoring
Details:
It was discovered that Netdata incorrectly handled parsing JSON input,
which could lead to a JSON injection. An attacker could possibly use
this issue to execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-18836)
It was discovered that Netdata incorrectly handled parsing HTTP headers,
which could lead to a HTTP header injection. An attacker could possibly
use this issue to cause a denial of service or leak sensitive information.
This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18837)
It was discovered that Netdata incorrectly handled parsing URLs, which
could lead to a log injection. An attacker could possibly use this issue
to consume system resources, resulting in a denial of service. This issue
only affected Ubuntu 18.04 LTS. (CVE-2018-18838)
It was discovered Netdata improperly authenticated API keys. An attacker
could possibly use this issue to leak sensitive information or execute
arbitrary code. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2023-22497)
It was discovered Fluent Bit, vendored in Netdata, incorrectly handled
parsing HTTP payloads. An attacker could possibly use this issue to
disrupt logging. This issue only affected Ubuntu 24.10. (CVE-2024-23722)
It was discovered that WebAssembly Micro Runtime, vendored in Netdata,
incorrectly handled memory. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.10.
(CVE-2024-34250, CVE-2024-34251)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
netdata-core 1.44.3-2ubuntu0.1
netdata-plugins-bash 1.44.3-2ubuntu0.1
netdata-web 1.44.3-2ubuntu0.1
Ubuntu 22.04 LTS
netdata-core 1.33.1-1ubuntu1+esm1
Available with Ubuntu Pro
netdata-plugins-bash 1.33.1-1ubuntu1+esm1
Available with Ubuntu Pro
netdata-web 1.33.1-1ubuntu1+esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
netdata-core 1.19.0-3ubuntu1+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
netdata 1.9.0+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
netdata-data 1.9.0+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
After a standard system update you need to restart Netdata to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7250-1
CVE-2018-18836, CVE-2018-18837, CVE-2018-18838, CVE-2023-22497,
CVE-2024-23722, CVE-2024-34250, CVE-2024-34251
Package Information:
https://launchpad.net/ubuntu/+source/netdata/1.44.3-2ubuntu0.1
Subscribe to:
Posts (Atom)