Episode 243

Episode 243

Update: 2024-12-20
Share

Description

Overview


It’s the end of the year for official duties for the Ubuntu Security team so we
take a look back on the security highlights of 2024 for Ubuntu and predict what is coming in 2025.


2024 Year in Review for Ubuntu Security (00:55 )


full-disclosure necromancy with zombie CVEs



Development of unprivileged user namespace restrictions for Ubuntu 24.04 LTS



Linux kernel becomes a CNA



Ubuntu participates in Pwn2Own Vancouver



xz-utils / SSH backdoor supply-chain attack



Linux Security Summit NA and EU



Release of Ubuntu 24.04 LTS



regreSSHion remote unauthenticated code execution vulnerability in OpenSSH



Various other high profile vulnerabilities



Ubuntu/Windows Dual-boot regression



AppArmor-based snap file prompting experimental feature



Predictions for 2025 (14:35 )



  • Increased use of AI to both spam projects with hallucinated CVEs (e.g. curl)
    but also to “aid” in dealing with that spam


  • More malware targeting Linux

    • didn’t mention it earlier but we covered a number of Linux malware teardowns
      this year and expect that trend to increase as Linux keeps growing in
      popularity



  • Full LSM stacking still won’t make it into the upstream Linux kernel

  • Integrity of code and data will play more of a role

    • both in terms of software supply chain and integrity of distro repos etc,
      but also efforts to try and guarantee the integrity of a Linux system
      itself - whether via new IPE LSM or other mechanisms - mainstream distros
      will start to care about integrity more



  • More collaboration across distros to aid in efforts to collectively handle
    deluge of CVEs

  • More efforts to try and fund OSS to learn from lessons of Heartbleed and xz-utils

    • some more and less successful



  • More interesting vulns in more software

    • During 2024 Qualys have done some of the most interesting vuln research on
      Linux - expect more from them and from others (whether aided by AI or not)




Get in contact


Comments 
In Channel
Episode 243

Episode 243

2024-12-2024:00

Episode 242

Episode 242

2024-11-2919:40

Episode 241

Episode 241

2024-11-1418:16

Episode 240

Episode 240

2024-10-3136:22

Episode 239

Episode 239

2024-10-1839:16

Episode 238

Episode 238

2024-10-0431:39

Episode 237

Episode 237

2024-09-2016:16

Episode 236

Episode 236

2024-09-0618:23

Episode 235

Episode 235

2024-08-2317:40

Episode 234

Episode 234

2024-08-0929:11

Episode 233

Episode 233

2024-08-0224:07

Episode 232

Episode 232

2024-07-0529:20

Episode 231

Episode 231

2024-06-2819:00

Episode 230

Episode 230

2024-06-2021:12

Episode 229

Episode 229

2024-05-3113:22

Episode 228

Episode 228

2024-05-2415:33

Episode 227

Episode 227

2024-05-0324:41

Episode 226

Episode 226

2024-04-1923:59

Episode 225

Episode 225

2024-04-1219:42

Episode 224

Episode 224

2024-04-0528:49

loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Episode 243

Episode 243

Ubuntu Security Team