-----BEGIN PGP SIGNATURE-----
wnsEABYIACMWIQSV2d7RU755utSnx3O7Ba3EKYsoKQUCZ63Q3AUDAAAAAAAKCRC7Ba3EKYsoKdGC
AQDhwFsrk6hLJXdoHOt05+c3MYoIFIaYnC0srqExoszz2AD+JdbXX0FUuIowTrZib8pVN1R9IG+u
qKXHDIILgiuxeAs=
=zNnn
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6846-3
February 13, 2025
ansible regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
USN-6846-2 caused some regression in ansible.
Software Description:
- ansible: Configuration management, deployment, and task execution system
Details:
USN-6846-1 fixed vulnerabilities in ansible. The update introduced a
regression in ansible. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ansible incorrectly handled certain inputs when
using tower_callback parameter. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-3697)
It was discovered that Ansible incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to perform a
Template Injection. (CVE-2023-5764)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
ansible 2.5.1+dfsg-1ubuntu0.1+esm4
Available with Ubuntu Pro
Ubuntu 16.04 LTS
ansible 2.0.0.2-2ubuntu1.3+esm4
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6846-3
https://ubuntu.com/security/notices/USN-6846-2
https://ubuntu.com/security/notices/USN-6846-1
https://launchpad.net/bugs/2097504
Thursday, February 13, 2025
[USN-7256-2] Ruby regression
==========================================================================
Ubuntu Security Notice USN-7256-2
February 13, 2025
ruby2.7 regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
USN-7256-1 caused some minor regressions in Ruby
Software Description:
- ruby2.7: Object-oriented scripting language
Details:
USN-7256-1 fixed vulnerabilities in Ruby. The update introduced a minor
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ruby incorrectly handled parsing of an XML document
that has specific XML characters in an attribute value using REXML gem. An
attacker could use this issue to cause Ruby to crash, resulting in a
denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
libruby2.7 2.7.0-5ubuntu1.17
ruby2.7 2.7.0-5ubuntu1.17
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7256-2
https://ubuntu.com/security/notices/USN-7256-1
https://launchpad.net/bugs/2097527
Package Information:
https://launchpad.net/ubuntu/+source/ruby2.7/2.7.0-5ubuntu1.17
Ubuntu Security Notice USN-7256-2
February 13, 2025
ruby2.7 regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
USN-7256-1 caused some minor regressions in Ruby
Software Description:
- ruby2.7: Object-oriented scripting language
Details:
USN-7256-1 fixed vulnerabilities in Ruby. The update introduced a minor
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ruby incorrectly handled parsing of an XML document
that has specific XML characters in an attribute value using REXML gem. An
attacker could use this issue to cause Ruby to crash, resulting in a
denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
libruby2.7 2.7.0-5ubuntu1.17
ruby2.7 2.7.0-5ubuntu1.17
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7256-2
https://ubuntu.com/security/notices/USN-7256-1
https://launchpad.net/bugs/2097527
Package Information:
https://launchpad.net/ubuntu/+source/ruby2.7/2.7.0-5ubuntu1.17
Wednesday, February 12, 2025
[USN-7266-1] digiKam vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmetb5sFAwAAAAAACgkQuGrtzot7pOcQ
2gv8COx7hL7OusDYNcBHl/l+AlW8SFHIAHJlltSjaJT/zHriIxk1RFyooXVECMM+qWM8eV0h/pzk
59Ujv9v2ZkNJC8PYnjBwLw30975nSBJebNAYKxlFXJBFiOPxW3sWW4YEvxrKX1V92HE/1pW1pgbS
QKdqLhwtXPJF5I5cZmeZKV4TvwjeSOEqzQBdiQvl3iIPCceXSExAbriJfM1HP5gGjDGXTH7Gj+0W
2JuQRfFnovmdFQrRD6FZu5IX+p37jMRrqIjlL2KOuuJWpRyKSW0MMoSE5ONWqV60xdaXn/TA/FBq
G0zPuWg2F1NqJseEZ41raAYZ1AlGMNAsMrM6nT4uzF8k1N76wM1cLyQhHrn9h4PyCUqqKBhthFdP
BcK2VWPhS8nltSVfTtgCaOnr+uBHB5E/Zx0lXjNThKflZitPHkQM6820RWi7Cf65hcxk/bGBIziC
PMC4iBbVMOEETzBpU/7h8LuM/67gGGOaC55snkKRWHaAm4mLyZZpwlGhgn55
=6ZnT
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7266-1
February 13, 2025
digikam vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in digiKam.
Software Description:
- digikam: digital photo management application for KDE
Details:
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-22628)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to cause a denial of service or execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-35530,
CVE-2020-35531, CVE-2020-35532, CVE-2020-35533)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 20.04 LTS. (CVE-2021-32142)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2023-1729)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
digikam 4:7.5.0-3ubuntu0.1~esm1
Available with Ubuntu Pro
showfoto 4:7.5.0-3ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
digikam 4:6.4.0+dfsg-3ubuntu0.1~esm1
Available with Ubuntu Pro
showfoto 4:6.4.0+dfsg-3ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
digikam 4:5.6.0-0ubuntu10+esm1
Available with Ubuntu Pro
showfoto 4:5.6.0-0ubuntu10+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
digikam 4:4.12.0-0ubuntu7+esm1
Available with Ubuntu Pro
showfoto 4:4.12.0-0ubuntu7+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7266-1
CVE-2017-0691, CVE-2020-19858, CVE-2020-22628, CVE-2020-35530,
CVE-2020-35531, CVE-2020-35532, CVE-2020-35533, CVE-2021-32142,
CVE-2023-1729
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmetb5sFAwAAAAAACgkQuGrtzot7pOcQ
2gv8COx7hL7OusDYNcBHl/l+AlW8SFHIAHJlltSjaJT/zHriIxk1RFyooXVECMM+qWM8eV0h/pzk
59Ujv9v2ZkNJC8PYnjBwLw30975nSBJebNAYKxlFXJBFiOPxW3sWW4YEvxrKX1V92HE/1pW1pgbS
QKdqLhwtXPJF5I5cZmeZKV4TvwjeSOEqzQBdiQvl3iIPCceXSExAbriJfM1HP5gGjDGXTH7Gj+0W
2JuQRfFnovmdFQrRD6FZu5IX+p37jMRrqIjlL2KOuuJWpRyKSW0MMoSE5ONWqV60xdaXn/TA/FBq
G0zPuWg2F1NqJseEZ41raAYZ1AlGMNAsMrM6nT4uzF8k1N76wM1cLyQhHrn9h4PyCUqqKBhthFdP
BcK2VWPhS8nltSVfTtgCaOnr+uBHB5E/Zx0lXjNThKflZitPHkQM6820RWi7Cf65hcxk/bGBIziC
PMC4iBbVMOEETzBpU/7h8LuM/67gGGOaC55snkKRWHaAm4mLyZZpwlGhgn55
=6ZnT
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7266-1
February 13, 2025
digikam vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in digiKam.
Software Description:
- digikam: digital photo management application for KDE
Details:
Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in
digiKam, did not correctly parse certain files. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)
It was discovered that Platinum Upnp SDK, vendored in digiKam, was
vulnerable to a path traversal attack. An attacker could possibly use this
issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-19858)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 20.04 LTS. (CVE-2020-22628)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to cause a denial of service or execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-35530,
CVE-2020-35531, CVE-2020-35532, CVE-2020-35533)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 20.04 LTS. (CVE-2021-32142)
It was discovered that LibRaw, vendored in digiKam, did not correctly
handle certain memory operations. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2023-1729)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
digikam 4:7.5.0-3ubuntu0.1~esm1
Available with Ubuntu Pro
showfoto 4:7.5.0-3ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
digikam 4:6.4.0+dfsg-3ubuntu0.1~esm1
Available with Ubuntu Pro
showfoto 4:6.4.0+dfsg-3ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
digikam 4:5.6.0-0ubuntu10+esm1
Available with Ubuntu Pro
showfoto 4:5.6.0-0ubuntu10+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
digikam 4:4.12.0-0ubuntu7+esm1
Available with Ubuntu Pro
showfoto 4:4.12.0-0ubuntu7+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7266-1
CVE-2017-0691, CVE-2020-19858, CVE-2020-22628, CVE-2020-35530,
CVE-2020-35531, CVE-2020-35532, CVE-2020-35533, CVE-2021-32142,
CVE-2023-1729
F42 Change Deadline - 100% Complete by February 18th
Hi all,
Please be advised that if you are a change owner for Fedora Linux 42,
you must have your change 100% complete[1] by 18 February 2025. We
will be entering Beta Freeze on this date also as per our release
schedule[2], and if your change is not completed, it may be deferred
to another Fedora Linux release. Please update your tracking bug(s)
for your change(s) to their latest status. A list of incomplete
changes will be submitted to FESCo before the change completion
deadline.
For any help you need, please do not hesitate to reach out to me.
Kindest regards,
Aoife
[1] https://docs.fedoraproject.org/en-US/program_management/changes_policy/#_change_process_milestones
[2] https://fedorapeople.org/groups/schedule/f-42/f-42-key-tasks.html
--
Aoife Moloney
Fedora Operations Architect
Fedora Project
Matrix: @amoloney:fedora.im
IRC: amoloney
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
Please be advised that if you are a change owner for Fedora Linux 42,
you must have your change 100% complete[1] by 18 February 2025. We
will be entering Beta Freeze on this date also as per our release
schedule[2], and if your change is not completed, it may be deferred
to another Fedora Linux release. Please update your tracking bug(s)
for your change(s) to their latest status. A list of incomplete
changes will be submitted to FESCo before the change completion
deadline.
For any help you need, please do not hesitate to reach out to me.
Kindest regards,
Aoife
[1] https://docs.fedoraproject.org/en-US/program_management/changes_policy/#_change_process_milestones
[2] https://fedorapeople.org/groups/schedule/f-42/f-42-key-tasks.html
--
Aoife Moloney
Fedora Operations Architect
Fedora Project
Matrix: @amoloney:fedora.im
IRC: amoloney
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
[USN-7238-4] Linux kernel (AWS) vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmes7KYFAwAAAAAACgkQZ0GeRcM5nt3x
Vgf9GN+bzXU7W0Y6n09lKMpQhIX1zeCdNrHn3OFQWp8PoP5f+nGgIpw+ZUQZ1ilWS0XBW0vxsPYJ
lJti/I+bp2c7Q6sSFMDynjlmYaK+z4R08a7L4vw/bb54UqWfp7I7qUSepfvTv7+m9rnJK+SECB+I
aSgXO0t7FfZrqD31G2UuXPiZuE0EGR24K9KcPBlkLH/LzWzBshU85+CrAz/ZtC91nNuBo7fhg0JN
C6ESSOhEpmNkHEFSv8HDeq6WFA8P/fWti50SV37AQ5xKYQUcvaEaZPc4TfkoDkUb4dMfq7hpvtKE
Y11B0KlgqoQC6xEZGyj8+svHGDgyljzwq12ooTHqgw==
=rYJf
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7238-4
February 12, 2025
linux-aws vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53103, CVE-2024-53164)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
linux-image-6.11.0-1008-aws 6.11.0-1008.8
linux-image-aws 6.11.0-1008.8
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7238-4
https://ubuntu.com/security/notices/USN-7238-3
https://ubuntu.com/security/notices/USN-7238-2
https://ubuntu.com/security/notices/USN-7238-1
CVE-2024-53103, CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-aws/6.11.0-1008.8
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmes7KYFAwAAAAAACgkQZ0GeRcM5nt3x
Vgf9GN+bzXU7W0Y6n09lKMpQhIX1zeCdNrHn3OFQWp8PoP5f+nGgIpw+ZUQZ1ilWS0XBW0vxsPYJ
lJti/I+bp2c7Q6sSFMDynjlmYaK+z4R08a7L4vw/bb54UqWfp7I7qUSepfvTv7+m9rnJK+SECB+I
aSgXO0t7FfZrqD31G2UuXPiZuE0EGR24K9KcPBlkLH/LzWzBshU85+CrAz/ZtC91nNuBo7fhg0JN
C6ESSOhEpmNkHEFSv8HDeq6WFA8P/fWti50SV37AQ5xKYQUcvaEaZPc4TfkoDkUb4dMfq7hpvtKE
Y11B0KlgqoQC6xEZGyj8+svHGDgyljzwq12ooTHqgw==
=rYJf
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7238-4
February 12, 2025
linux-aws vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53103, CVE-2024-53164)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
linux-image-6.11.0-1008-aws 6.11.0-1008.8
linux-image-aws 6.11.0-1008.8
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7238-4
https://ubuntu.com/security/notices/USN-7238-3
https://ubuntu.com/security/notices/USN-7238-2
https://ubuntu.com/security/notices/USN-7238-1
CVE-2024-53103, CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-aws/6.11.0-1008.8
[USN-7236-3] Linux kernel (Azure) vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmes7IYFAwAAAAAACgkQZ0GeRcM5nt2L
nAf9FpynjjrWFwhvjZkVvdMDxQp+FU/qfFEH6M9tDNCi9PFfQ6bWgt54k4Cc36oVA3coL8VKYsZc
7HtigiwidfkyKMozB0NXXu2NZq9/M1R1E3PrkyAU8emmbGRvMM3FlvHisRDWAqJf+oIxJ0MCHp5T
oyuaiuND34O8PBz7UiYqEQAH5aRoGQPsDryDg36BU7Mg79ov1ZxFcQ2QLjOilsg9hO04boCuFFNT
28M62QbDZ4/q7Aovfa9typxjDrlfzwg5pkzO9w3gsyzKw/lnjIizwH0sH++We3lwpro2IQUTryeL
WQlZzE3GYKLjK7PxPRzn6VfD2jKHbN5BccM6CsMDNg==
=Ajcl
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7236-3
February 12, 2025
linux-azure-6.8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure-6.8: Linux kernel for Microsoft Azure cloud systems
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Netfilter;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53164, CVE-2024-53103, CVE-2024-53141)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
linux-image-6.8.0-1021-azure 6.8.0-1021.25~22.04.1
linux-image-6.8.0-1021-azure-fde 6.8.0-1021.25~22.04.1
linux-image-azure 6.8.0-1021.25~22.04.1
linux-image-azure-fde 6.8.0-1021.25~22.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7236-3
https://ubuntu.com/security/notices/USN-7236-2
https://ubuntu.com/security/notices/USN-7236-1
CVE-2024-53103, CVE-2024-53141, CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure-6.8/6.8.0-1021.25~22.04.1
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmes7IYFAwAAAAAACgkQZ0GeRcM5nt2L
nAf9FpynjjrWFwhvjZkVvdMDxQp+FU/qfFEH6M9tDNCi9PFfQ6bWgt54k4Cc36oVA3coL8VKYsZc
7HtigiwidfkyKMozB0NXXu2NZq9/M1R1E3PrkyAU8emmbGRvMM3FlvHisRDWAqJf+oIxJ0MCHp5T
oyuaiuND34O8PBz7UiYqEQAH5aRoGQPsDryDg36BU7Mg79ov1ZxFcQ2QLjOilsg9hO04boCuFFNT
28M62QbDZ4/q7Aovfa9typxjDrlfzwg5pkzO9w3gsyzKw/lnjIizwH0sH++We3lwpro2IQUTryeL
WQlZzE3GYKLjK7PxPRzn6VfD2jKHbN5BccM6CsMDNg==
=Ajcl
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7236-3
February 12, 2025
linux-azure-6.8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-azure-6.8: Linux kernel for Microsoft Azure cloud systems
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Netfilter;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53164, CVE-2024-53103, CVE-2024-53141)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
linux-image-6.8.0-1021-azure 6.8.0-1021.25~22.04.1
linux-image-6.8.0-1021-azure-fde 6.8.0-1021.25~22.04.1
linux-image-azure 6.8.0-1021.25~22.04.1
linux-image-azure-fde 6.8.0-1021.25~22.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7236-3
https://ubuntu.com/security/notices/USN-7236-2
https://ubuntu.com/security/notices/USN-7236-1
CVE-2024-53103, CVE-2024-53141, CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-azure-6.8/6.8.0-1021.25~22.04.1
[USN-7235-3] Linux kernel (AWS) vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmes7GoFAwAAAAAACgkQZ0GeRcM5nt35
dwgAnMuuN761mhgRAfFYq2d2MIrz0jPvimW7sDL7l1uQAptA4kHNQgE0KsoBVSbgMUHOKn64E6fb
ZpP90RqmFXtVo2w10ytpWm6waJIxS0lM5rEjcwPlAV/3BOb7K5dr0vhglcWHBc4Rt0dtHo+h9DN+
vrZ+AJRrNXqw+N9qVqgzAOZWH63htlEpPwKndCht1CWwSDKiHuIsOnH68n2Of88/J14Tqqx44NcX
6R6WQETTWlGsnMaQM4gHsU7pjVF7XR8zagvYRCD/mppsrAJICXzq9/N4eWD0KeYS8kC2e71/kWUu
S/+Jpyf47vddmyNl1J68gKlDg/7cS5btR2zrVaLjbQ==
=h7IP
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7235-3
February 12, 2025
linux-aws-5.15 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-aws-5.15: Linux kernel for Amazon Web Services (AWS) systems
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Netfilter;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53164, CVE-2024-53103, CVE-2024-53141)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.15.0-1077-aws 5.15.0-1077.84~20.04.1
linux-image-aws 5.15.0.1077.84~20.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7235-3
https://ubuntu.com/security/notices/USN-7235-2
https://ubuntu.com/security/notices/USN-7235-1
CVE-2024-53103, CVE-2024-53141, CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-aws-5.15/5.15.0-1077.84~20.04.1
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmes7GoFAwAAAAAACgkQZ0GeRcM5nt35
dwgAnMuuN761mhgRAfFYq2d2MIrz0jPvimW7sDL7l1uQAptA4kHNQgE0KsoBVSbgMUHOKn64E6fb
ZpP90RqmFXtVo2w10ytpWm6waJIxS0lM5rEjcwPlAV/3BOb7K5dr0vhglcWHBc4Rt0dtHo+h9DN+
vrZ+AJRrNXqw+N9qVqgzAOZWH63htlEpPwKndCht1CWwSDKiHuIsOnH68n2Of88/J14Tqqx44NcX
6R6WQETTWlGsnMaQM4gHsU7pjVF7XR8zagvYRCD/mppsrAJICXzq9/N4eWD0KeYS8kC2e71/kWUu
S/+Jpyf47vddmyNl1J68gKlDg/7cS5btR2zrVaLjbQ==
=h7IP
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7235-3
February 12, 2025
linux-aws-5.15 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-aws-5.15: Linux kernel for Amazon Web Services (AWS) systems
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Netfilter;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53164, CVE-2024-53103, CVE-2024-53141)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.15.0-1077-aws 5.15.0-1077.84~20.04.1
linux-image-aws 5.15.0.1077.84~20.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7235-3
https://ubuntu.com/security/notices/USN-7235-2
https://ubuntu.com/security/notices/USN-7235-1
CVE-2024-53103, CVE-2024-53141, CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-aws-5.15/5.15.0-1077.84~20.04.1
[USN-7234-4] Linux kernel (AWS) vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmes7FUFAwAAAAAACgkQZ0GeRcM5nt21
aQf+IVHEygUDMxh9x30fqp6ep7nrgv7CwRp9XrDrVSsJVhaQYO+GeCjR2/eeicfXYJEVUC0UvEtW
5aofXj8BCC3D/32YBkDWYdhddaPgRnS41+g1sHrVSk1wIWwXRB7AwYUDtfwUN7DOQ4xUqTu35nrg
HymErcmNrwp6NMCk3i/7f3WyPpeGiXGrv3vNfq4VtI3UEOdxgUPeEi8dgMW+C5AbHqxoYRwOHiWX
LjLfEOZ68nTXh2Qx3VcmXVsoeNQOBNnKxV2iiAd2nM/OwGhBrIxCMpzxdGCf2kjTKEexYx0z4TOH
8aYYNhJK6r3elTE9nKc24gGcipc3jebaLOz8wje7Xg==
=NkW7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7234-4
February 12, 2025
linux-aws vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
Details:
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2023-21400)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- TTY drivers;
- Netfilter;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53141, CVE-2024-53103, CVE-2024-40967, CVE-2024-53164)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.4.0-1139-aws 5.4.0-1139.149
linux-image-aws-lts-20.04 5.4.0.1139.136
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7234-4
https://ubuntu.com/security/notices/USN-7234-3
https://ubuntu.com/security/notices/USN-7234-2
https://ubuntu.com/security/notices/USN-7234-1
CVE-2023-21400, CVE-2024-40967, CVE-2024-53103, CVE-2024-53141,
CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1139.149
wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmes7FUFAwAAAAAACgkQZ0GeRcM5nt21
aQf+IVHEygUDMxh9x30fqp6ep7nrgv7CwRp9XrDrVSsJVhaQYO+GeCjR2/eeicfXYJEVUC0UvEtW
5aofXj8BCC3D/32YBkDWYdhddaPgRnS41+g1sHrVSk1wIWwXRB7AwYUDtfwUN7DOQ4xUqTu35nrg
HymErcmNrwp6NMCk3i/7f3WyPpeGiXGrv3vNfq4VtI3UEOdxgUPeEi8dgMW+C5AbHqxoYRwOHiWX
LjLfEOZ68nTXh2Qx3VcmXVsoeNQOBNnKxV2iiAd2nM/OwGhBrIxCMpzxdGCf2kjTKEexYx0z4TOH
8aYYNhJK6r3elTE9nKc24gGcipc3jebaLOz8wje7Xg==
=NkW7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7234-4
February 12, 2025
linux-aws vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
Details:
Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux
kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
(CVE-2023-21400)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- TTY drivers;
- Netfilter;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-53141, CVE-2024-53103, CVE-2024-40967, CVE-2024-53164)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
linux-image-5.4.0-1139-aws 5.4.0-1139.149
linux-image-aws-lts-20.04 5.4.0.1139.136
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-7234-4
https://ubuntu.com/security/notices/USN-7234-3
https://ubuntu.com/security/notices/USN-7234-2
https://ubuntu.com/security/notices/USN-7234-1
CVE-2023-21400, CVE-2024-40967, CVE-2024-53103, CVE-2024-53141,
CVE-2024-53164
Package Information:
https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1139.149
Re: github2fedmsg and fedmsg EOL date changed to 13th February
Hello everyone,
this is a reminder that fedmsg and github2fedmsg will go away tomorrow
on 13th February.
On behalf of Fedora Infrastructure team,
Michal 'Zlopez'
On 2/3/25 09:32, Michal Konecny wrote:
> Hello everyone,
>
> Fedora CoreOS team reached to us to postpone the date of
> decommissioning github2fedmsg and fedmsg in Fedora Infrastructure as
> they still need some time to migrate.
>
> I will still start working on this in our staging environment, but in
> production the new date is 13th February.
>
> On behalf of Fedora Infrastructure team,
> Michal 'Zlopez'
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
this is a reminder that fedmsg and github2fedmsg will go away tomorrow
on 13th February.
On behalf of Fedora Infrastructure team,
Michal 'Zlopez'
On 2/3/25 09:32, Michal Konecny wrote:
> Hello everyone,
>
> Fedora CoreOS team reached to us to postpone the date of
> decommissioning github2fedmsg and fedmsg in Fedora Infrastructure as
> they still need some time to migrate.
>
> I will still start working on this in our staging environment, but in
> production the new date is 13th February.
>
> On behalf of Fedora Infrastructure team,
> Michal 'Zlopez'
--
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
[USN-7265-1] BlueZ vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmesZ2oFAwAAAAAACgkQuGrtzot7pOei
iQv8CTJsGf5mUcymBmxZV34UcnF3qLITjmIIT8YtyfXLGx9x+fgbhNuK5MaspqnganqqcaDHDHUL
lIibdrKDfcrOshMZcpbY+QG325IrbJCF4ZJKWIBnUd2jtGmnlp7tXvkgZpigj9IMCyah1VFUJIiF
Ey7K757YOBE/X4lOQlTZqmxMyS42FFPG47EjlUf9OQMJyPMwPVay9adBwDq6gchYu/Ca514jtmNI
0Jk5q1Vc4N0aacBYXlZcM38x9N82rdb3dvYbRg2MxWSbsVjLeqjQ+/QoCAfi2nkjoN5BZeT+a3tO
Wz0GwvRavRPqwiptQYs/YM2XzRUA0+KKHg1t0FSYkA8NBv8MBg01IsDlWG0Cv9neaNrasyA6i6PN
QQY6CLKgkEimBBYfBwKJdv9jtDbx9msoDIa6GeePlXEUUIElhjxtjFtrT2utMaFLdFDxnPI+L32F
Wjm1LcBqMPbAHLfkUpLfGDZ6RVczUtY1Vhw5X78eIxG3rfcth70yrhCtJehb
=/r8C
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7265-1
February 12, 2025
bluez vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
BlueZ could be made to crash or run programs as your login if it received
specially crafted Bluetooth requests.
Software Description:
- bluez: Bluetooth tools and daemons
Details:
Julian Rauchberger discovered that BlueZ did not correctly handle certain
memory operations. An attacker could possibly use this issue to leak
sensitive information or execute arbitrary code.
(CVE-2019-8921, CVE-2019-8922)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS
bluez 5.37-0ubuntu5.3+esm5
Available with Ubuntu Pro
libbluetooth3 5.37-0ubuntu5.3+esm5
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7265-1
CVE-2019-8921, CVE-2019-8922
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmesZ2oFAwAAAAAACgkQuGrtzot7pOei
iQv8CTJsGf5mUcymBmxZV34UcnF3qLITjmIIT8YtyfXLGx9x+fgbhNuK5MaspqnganqqcaDHDHUL
lIibdrKDfcrOshMZcpbY+QG325IrbJCF4ZJKWIBnUd2jtGmnlp7tXvkgZpigj9IMCyah1VFUJIiF
Ey7K757YOBE/X4lOQlTZqmxMyS42FFPG47EjlUf9OQMJyPMwPVay9adBwDq6gchYu/Ca514jtmNI
0Jk5q1Vc4N0aacBYXlZcM38x9N82rdb3dvYbRg2MxWSbsVjLeqjQ+/QoCAfi2nkjoN5BZeT+a3tO
Wz0GwvRavRPqwiptQYs/YM2XzRUA0+KKHg1t0FSYkA8NBv8MBg01IsDlWG0Cv9neaNrasyA6i6PN
QQY6CLKgkEimBBYfBwKJdv9jtDbx9msoDIa6GeePlXEUUIElhjxtjFtrT2utMaFLdFDxnPI+L32F
Wjm1LcBqMPbAHLfkUpLfGDZ6RVczUtY1Vhw5X78eIxG3rfcth70yrhCtJehb
=/r8C
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7265-1
February 12, 2025
bluez vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
BlueZ could be made to crash or run programs as your login if it received
specially crafted Bluetooth requests.
Software Description:
- bluez: Bluetooth tools and daemons
Details:
Julian Rauchberger discovered that BlueZ did not correctly handle certain
memory operations. An attacker could possibly use this issue to leak
sensitive information or execute arbitrary code.
(CVE-2019-8921, CVE-2019-8922)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS
bluez 5.37-0ubuntu5.3+esm5
Available with Ubuntu Pro
libbluetooth3 5.37-0ubuntu5.3+esm5
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7265-1
CVE-2019-8921, CVE-2019-8922
Tuesday, February 11, 2025
[USN-7264-1] OpenSSL vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmerusAFAwAAAAAACgkQZWnYVadEvpNv
wA/+P3ZIeLa/n/D+/kkethlgVfbw/6i4FmdGq3F1SCs81mSZf5gT9GZke9iXvOfC45LTnunLbNgs
UQhcvStLa2wBn4u4jUhgOQFbplRPxKkf07DnMCBa7TsLBJQr0149GNOcKR5Bsu8hA51O5Hz2lfjV
gA0vXFxYgxpzPYBxN3JJZnewY9YmpRA8DU46uoj/lpg5ubZ9+TOnsqgyFTDcxoozsionHpfnVSTI
ByywxssO8kd+vWNladuoVVhsk88xaIoKW6xiARUNWCkvsx2fEh08dGde4tl/1BySRxwt8NqErbO4
aXwYj2Duvel/hvcaKEk+N3nm+5HNkoDLcemkLFnd7UhuVzj/Vp6NltI/rpfUaa7UvyM9ysjlEvWl
LHFA6TbAapWBTQK03R5xQQIi5NjHre0dOeuS2F+d1E+Kbw49qGaipfxvR52vSbd6JZJvx7MPe7Z/
rDv2647mjdceqe/KAsmZx2TLl+1SfCUHdXtNkUlC9gZGI3wFImrF+WeEfcz3V58iAQY2hStVfppj
mkX/RjlZTeJ5awDrepA4b0gHKon/I0Y9MfCB88BWVUD+acg3ENWUy5eWNOrfTMhYpALm2aLpwjKg
ubcX3pJUvhWA5Xlfyz15JFcUpqZH5AQ3jSigtqJ7Q2utFqjS8ZWRmmFC7LPTT7YF5t0VZkouWKkK
qCM=
=unm0
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7264-1
February 11, 2025
openssl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
Summary:
Several security issues were fixed in OpenSSL.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
It was discovered that OpenSSL clients incorrectly handled authenticating
servers using RFC7250 Raw Public Keys. In certain cases, the connection
will not abort as expected, possibly causing the communication to be
intercepted. (CVE-2024-12797)
George Pantelakis and Alicja Kario discovered that OpenSSL had a timing
side-channel when performing ECDSA signature computations. A remote
attacker could possibly use this issue to recover private data.
(CVE-2024-13176)
It was discovered that OpenSSL incorrectly handled certain memory
operations when using low-level GF(2^m) elliptic curve APIs with untrusted
explicit values for the field polynomial. When being used in this uncommon
fashion, a remote attacker could use this issue to cause OpenSSL to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-9143)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libssl3t64 3.3.1-2ubuntu2.1
openssl 3.3.1-2ubuntu2.1
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7264-1
CVE-2024-12797, CVE-2024-13176, CVE-2024-9143
Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.3.1-2ubuntu2.1
wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmerusAFAwAAAAAACgkQZWnYVadEvpNv
wA/+P3ZIeLa/n/D+/kkethlgVfbw/6i4FmdGq3F1SCs81mSZf5gT9GZke9iXvOfC45LTnunLbNgs
UQhcvStLa2wBn4u4jUhgOQFbplRPxKkf07DnMCBa7TsLBJQr0149GNOcKR5Bsu8hA51O5Hz2lfjV
gA0vXFxYgxpzPYBxN3JJZnewY9YmpRA8DU46uoj/lpg5ubZ9+TOnsqgyFTDcxoozsionHpfnVSTI
ByywxssO8kd+vWNladuoVVhsk88xaIoKW6xiARUNWCkvsx2fEh08dGde4tl/1BySRxwt8NqErbO4
aXwYj2Duvel/hvcaKEk+N3nm+5HNkoDLcemkLFnd7UhuVzj/Vp6NltI/rpfUaa7UvyM9ysjlEvWl
LHFA6TbAapWBTQK03R5xQQIi5NjHre0dOeuS2F+d1E+Kbw49qGaipfxvR52vSbd6JZJvx7MPe7Z/
rDv2647mjdceqe/KAsmZx2TLl+1SfCUHdXtNkUlC9gZGI3wFImrF+WeEfcz3V58iAQY2hStVfppj
mkX/RjlZTeJ5awDrepA4b0gHKon/I0Y9MfCB88BWVUD+acg3ENWUy5eWNOrfTMhYpALm2aLpwjKg
ubcX3pJUvhWA5Xlfyz15JFcUpqZH5AQ3jSigtqJ7Q2utFqjS8ZWRmmFC7LPTT7YF5t0VZkouWKkK
qCM=
=unm0
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7264-1
February 11, 2025
openssl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
Summary:
Several security issues were fixed in OpenSSL.
Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools
Details:
It was discovered that OpenSSL clients incorrectly handled authenticating
servers using RFC7250 Raw Public Keys. In certain cases, the connection
will not abort as expected, possibly causing the communication to be
intercepted. (CVE-2024-12797)
George Pantelakis and Alicja Kario discovered that OpenSSL had a timing
side-channel when performing ECDSA signature computations. A remote
attacker could possibly use this issue to recover private data.
(CVE-2024-13176)
It was discovered that OpenSSL incorrectly handled certain memory
operations when using low-level GF(2^m) elliptic curve APIs with untrusted
explicit values for the field polynomial. When being used in this uncommon
fashion, a remote attacker could use this issue to cause OpenSSL to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2024-9143)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
libssl3t64 3.3.1-2ubuntu2.1
openssl 3.3.1-2ubuntu2.1
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7264-1
CVE-2024-12797, CVE-2024-13176, CVE-2024-9143
Package Information:
https://launchpad.net/ubuntu/+source/openssl/3.3.1-2ubuntu2.1
Monday, February 10, 2025
[USN-7263-1] Firefox vulnerabilities
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEAPYWTpwtIbr7xH4OWNrRIKaTkWcFAmeqyD8FAwAAAAAACgkQWNrRIKaTkWe4
ZQ//S/uS0s/Jk7S+6lEPcsDAMiDmrurcSc/pMs5t7Uly5UJV6CuWzor1qKteZRMjX4Ts2Ra52C9Y
Bgt/GLNEpqPYNBShKk3gZGW/LCP7Y2Z0WCu1JroHcGxT1R7hr03xtoijFCXkz0WhgGu3D9Ebs7kW
inzzJWAwOsTdUvLe6CSoyAPZRZVPaotEgMZpUcZYuqzyGr2kVUaJrLs5xKQYFvG0vw5jfHYUP27c
VYbIE5lV1F2WZfpr8SfYJEk6Lac6UHxqZ/2+zqVuIx+isVcjjr2IsYrWXF/D2V/HLfPTzqq0Y9wh
6/niefFEQk5KYvjOG7I6B7UJVxqGxQAc8LPUUHQ50w+CHBg50JhPMJbTeCxmPQa6hEr2AxZEeYZE
v/yQIE18UmofbqTkEOt9mQgmyd6hsAkfXQYYk/v1nDoOUlZ/dOnFioa9q0MBD7zsSsvWIHehu+04
8OD8iDZ0kcnUI+N6Ur4LSx+2FcsFi8IgOCdl4sFPQozlpdNfHSRB7epXxXCWtokQO7PYK3/pW8Yo
rWW6BACvT4X3HhBNCEJ2ZZqACfURQK5fsup3hNngBBs3XzNTJyuBC3+MXJs8IVz277p46E3/DN4M
/He6fpQi3EREs8qyf/p5ISZUNmNoqSPT4ldSvYZZ2q66x/3tpdvF/hhuIK66qe79w30HvhK84ClH
flk=
=c3hA
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7263-1
February 11, 2025
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2025-1011,
CVE-2025-1013, CVE-2025-1014, CVE-2025-1016, CVE-2025-1017, CVE-2025-1018,
CVE-2025-1019, CVE-2025-1020)
Ivan Fratric discovered that Firefox did not properly handle XSLT data,
leading to a use-after-free vulnerability. An attacker could potentially
exploit this issue to cause a denial of service, or execute arbitrary code.
(CVE-2025-1009)
Atte Kettunen discovered that Firefox did not properly manage memory in
the Custom Highlight API, leading to a use-after-free vulnerability. An
attacker could potentially exploit this issue to cause a denial of service,
or execute arbitrary code. (CVE-2025-1010)
Nils Bars discovered that Firefox did not properly manage memory during
concurrent delazification, leading to a use-after-free vulnerability.
An attacker could potentially exploit this issue to cause a denial of
service, or execute arbitrary code. (CVE-2025-1012)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
firefox 135.0+build2-0ubuntu0.20.04.1
After a standard system update you need to restart Firefox to make all the
necessary changes
References:
https://ubuntu.com/security/notices/USN-7263-1
CVE-2025-1009, CVE-2025-1010, CVE-2025-1011, CVE-2025-1012,
CVE-2025-1013, CVE-2025-1014, CVE-2025-1016, CVE-2025-1017,
CVE-2025-1018, CVE-2025-1019, CVE-2025-1020
Package Information:
https://launchpad.net/ubuntu/+source/firefox/135.0+build2-0ubuntu0.20.04.1
wsF5BAABCAAjFiEEAPYWTpwtIbr7xH4OWNrRIKaTkWcFAmeqyD8FAwAAAAAACgkQWNrRIKaTkWe4
ZQ//S/uS0s/Jk7S+6lEPcsDAMiDmrurcSc/pMs5t7Uly5UJV6CuWzor1qKteZRMjX4Ts2Ra52C9Y
Bgt/GLNEpqPYNBShKk3gZGW/LCP7Y2Z0WCu1JroHcGxT1R7hr03xtoijFCXkz0WhgGu3D9Ebs7kW
inzzJWAwOsTdUvLe6CSoyAPZRZVPaotEgMZpUcZYuqzyGr2kVUaJrLs5xKQYFvG0vw5jfHYUP27c
VYbIE5lV1F2WZfpr8SfYJEk6Lac6UHxqZ/2+zqVuIx+isVcjjr2IsYrWXF/D2V/HLfPTzqq0Y9wh
6/niefFEQk5KYvjOG7I6B7UJVxqGxQAc8LPUUHQ50w+CHBg50JhPMJbTeCxmPQa6hEr2AxZEeYZE
v/yQIE18UmofbqTkEOt9mQgmyd6hsAkfXQYYk/v1nDoOUlZ/dOnFioa9q0MBD7zsSsvWIHehu+04
8OD8iDZ0kcnUI+N6Ur4LSx+2FcsFi8IgOCdl4sFPQozlpdNfHSRB7epXxXCWtokQO7PYK3/pW8Yo
rWW6BACvT4X3HhBNCEJ2ZZqACfURQK5fsup3hNngBBs3XzNTJyuBC3+MXJs8IVz277p46E3/DN4M
/He6fpQi3EREs8qyf/p5ISZUNmNoqSPT4ldSvYZZ2q66x/3tpdvF/hhuIK66qe79w30HvhK84ClH
flk=
=c3hA
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7263-1
February 11, 2025
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2025-1011,
CVE-2025-1013, CVE-2025-1014, CVE-2025-1016, CVE-2025-1017, CVE-2025-1018,
CVE-2025-1019, CVE-2025-1020)
Ivan Fratric discovered that Firefox did not properly handle XSLT data,
leading to a use-after-free vulnerability. An attacker could potentially
exploit this issue to cause a denial of service, or execute arbitrary code.
(CVE-2025-1009)
Atte Kettunen discovered that Firefox did not properly manage memory in
the Custom Highlight API, leading to a use-after-free vulnerability. An
attacker could potentially exploit this issue to cause a denial of service,
or execute arbitrary code. (CVE-2025-1010)
Nils Bars discovered that Firefox did not properly manage memory during
concurrent delazification, leading to a use-after-free vulnerability.
An attacker could potentially exploit this issue to cause a denial of
service, or execute arbitrary code. (CVE-2025-1012)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
firefox 135.0+build2-0ubuntu0.20.04.1
After a standard system update you need to restart Firefox to make all the
necessary changes
References:
https://ubuntu.com/security/notices/USN-7263-1
CVE-2025-1009, CVE-2025-1010, CVE-2025-1011, CVE-2025-1012,
CVE-2025-1013, CVE-2025-1014, CVE-2025-1016, CVE-2025-1017,
CVE-2025-1018, CVE-2025-1019, CVE-2025-1020
Package Information:
https://launchpad.net/ubuntu/+source/firefox/135.0+build2-0ubuntu0.20.04.1
Subscribe to:
Posts (Atom)