Episode 225
Update: 2024-04-12
Description
Overview
This week we cover the recent reports of a new local privilege escalation
exploit against the Linux kernel, follow-up on the xz-utils backdoor from last
week and it’s the beta release of Ubuntu 24.04 LTS - plus we talk security
vulnerabilities in the X Server, Django, util-linux and more.
This week in Ubuntu Security Updates
76 unique CVEs addressed
[LSN-0102-1] Linux kernel vulnerability (00:53 )
- 6 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS)
- All covered in previous episodes
- netfilter UAF ([USN-6700-1] Linux kernel vulnerabilities from Episode 223)
- OOB write in KTLS ([USN-6648-1] Linux kernel vulnerabilities from Episode 220)
- UAF in AppleTalk network driver ([USN-6648-1] Linux kernel vulnerabilities from Episode 220)
- NULL ptr deref in TLS impl ([LSN-0100-1] Linux kernel vulnerability from Episode 219)
- Memory leak in netfilter ([USN-6383-1] Linux kernel vulnerabilities from Episode 210)
Kernel type | 22.04 | 20.04 | 18.04 | 16.04 | 14.04 |
---|---|---|---|---|---|
aws | 102.1 | 102.1 | 102.1 | 102.1 | — |
aws-5.15 | — | 102.1 | — | — | — |
aws-5.4 | — | — | 102.1 | — | — |
aws-6.5 | 102.1 | — | — | — | — |
aws-hwe | — | — | — | 102.1 | — |
azure | 102.1 | 102.1 | — | 102.1 | — |
azure-4.15 | — | — | 102.1 | — | — |
azure-5.4 | — | — | 102.1 | — | — |
azure-6.5 | 102.1 | — | — | — | — |
gcp | 102.1 | 102.1 | — | 102.1 | — |
gcp-4.15 | — | — | 102.1 | — | — |
gcp-5.15 | — | 102.1 | — | — | — |
gcp-5.4 | — | — | 102.1 | — | — |
gcp-6.5 | 102.1 | — | — | — | — |
generic-4.15 | — | — | 102.1 | 102.1 | — |
generic-4.4 | — | — | — | 102.1 | 102.1 |
generic-5.15 | — | 102.1 | — | — | — |
generic-5.4 | — | 102.1 | 102.1 | — | — |
gke | 102.1 | 102.1 | — | — | — |
gke-5.15 | — | 102.1 | — | — | — |
gkeop | — | 102.1 | — | — | — |
hwe-6.5 | 102.1 | — | — | — | — |
ibm | 102.1 | 102.1 | — | — | — |
ibm-5.15 | — | 102.1 | — | — | — |
linux | 102.1 | — | — | — | — |
lowlatency | 102.1 | — | — | — | — |
lowlatency-4.15 | — | — | 102.1 | 102.1 | — |
lowlatency-4.4 | — | — | — | 102.1 | 102.1 |
lowlatency-5.15 | — | 102.1 | — | — | — |
lowlatency-5.4 | — | 102.1 | 102.1 | — | — |
canonical-livepatch status
[USN-6710-2] Firefox regressions (01:54 )
- 2 CVEs addressed in Focal (20.04 LTS)
- 124.0.2
- In particular fixes to allow firefox when installed directly from Mozilla to
work under 24.04 LTS with the new AppArmor userns restrictions - As discussed in previous episodes, default profile allows to use userns but
then to be blocked on getting additional capabilities - Firefox would
previously try and do both a new userns and a new PID NS in one call - which
would be blocked - now split this into two separate calls so the userns can
succeed but pidns will be denied (since requiresCAP_SYS_ADMIN
) - but then
firefox correctly detects this and falls back to the correct behaviour
- In particular fixes to allow firefox when installed directly from Mozilla to
[USN-6721-1] X.Org X Server vulnerabilities (04:11 )
- 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM (16.04 ESM), Bionic ESM (18.04 ESM), Focal (20.04 LTS), Jammy (22.04 LTS), Mantic (23.10)
- Various OOB reads -> crash / info leaks when handling byte-swapped length
values - able to be easily triggered by a client who is using a different
endianness than the X server - UAF in glyph handling -> crash / RCE
[USN-6721-2] X.Org X Server regression
- 4 CVEs addressed in Trusty ESM (14.04 ESM), Xenial ESM
Comments
Top Podcasts
The Best New Comedy Podcast Right Now – June 2024The Best News Podcast Right Now – June 2024The Best New Business Podcast Right Now – June 2024The Best New Sports Podcast Right Now – June 2024The Best New True Crime Podcast Right Now – June 2024The Best New Joe Rogan Experience Podcast Right Now – June 20The Best New Dan Bongino Show Podcast Right Now – June 20The Best New Mark Levin Podcast – June 2024
In Channel