You are here
Home > Preporuke > Sigurnosni nedostaci jezgre operacijskog sustava

Sigurnosni nedostaci jezgre operacijskog sustava

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4096-1
August 13, 2019

linux-aws, linux-aws-hwe vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.04
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

The system could be made to expose sensitive information.

Software Description:
– linux-aws: Linux kernel for Amazon Web Services (AWS) systems
– linux-aws-hwe: Linux kernel for Amazon Web Services (AWS-HWE) systems

Details:

Andrei Vlad Lutas and Dan Lutas discovered that some x86 processors
incorrectly handle SWAPGS instructions during speculative execution. A
local attacker could use this to expose sensitive information (kernel
memory).

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
linux-image-5.0.0-1012-aws 5.0.0-1012.13
linux-image-aws 5.0.0.1012.12

Ubuntu 18.04 LTS:
linux-image-4.15.0-1045-aws 4.15.0-1045.47
linux-image-aws 4.15.0.1045.44

Ubuntu 16.04 LTS:
linux-image-4.15.0-1045-aws 4.15.0-1045.47~16.04.1
linux-image-aws-hwe 4.15.0.1045.45

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4096-1
CVE-2019-1125

Package Information:
https://launchpad.net/ubuntu/+source/linux-aws/5.0.0-1012.13
https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1045.47
https://launchpad.net/ubuntu/+source/linux-aws-hwe/4.15.0-1045.47~16.04.1

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl1S7VcACgkQLwmejQBe
gfS5Xg//WW++HmQLy+AI2syyO6/JrU/1ZAhu25cAwVC6fsH3Bz76odTdjYi+BxW7
EkA3QUp/Stu+Y40QAzMR7wmp1nSljatQux8YrClASGqCiigEQZX7yR55ZI6IxtSe
gjDYQwUb0tDA5C8cFTM8JlFo8joaazlHiThdtfztFspdxyZhMQ/qjSQgMRjMYA/p
tcVYIH9Rzzy9A+xagzI7PchUU/k6FVK8chz3d6j2qjEusXUxfkURDHDW2dmyhOpl
v9xDdzayqtzBvNSUWmQrSSem3LWlvbShy8a344g4MwgYhLEf7hC7yQB3/Uj+K835
eOBUZOKrlAc9I4HPAhCuwPGKlfDoMw0RlGvWFY6oGP6SgMiQ4etQkzeqXFUG6aCH
jNpfBU3otXs+5yzJ78vQoNXcU4IIl5kH5UC5Xk7wpI2zzj4P8tUyirIrR8QD6n7Q
9EcKBemXbOzSZmPknKfpEamaUjBmlE8LgDae5a1BJhGqpqqS59+0E671VQZt5c9S
kOPSZZc5RoLCPfbIpvQPSaXUvoYgUKQ/dexAh2jmP/qYSeXWRPJPm97ZZbfaDp60
YXQL0UAxvrqbrFCHoh+SmH+UG+SJwQlSzaFvuicBrMunskwDM5O6T4P6lMYMZ1T7
6RxA0zwNAn7QO2tJt413lqweeYbEyF1HQIN26DfyrPaQnQaQbfM=
=HFlQ
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4095-2
August 13, 2019

linux-lts-xenial, linux-aws vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux-aws: Linux kernel for Amazon Web Services (AWS) systems
– linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty

Details:

USN-4095-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM.

Eli Biham and Lior Neumann discovered that the Bluetooth implementation in
the Linux kernel did not properly validate elliptic curve parameters during
Diffie-Hellman key exchange in some situations. An attacker could use this
to expose sensitive information. (CVE-2018-5383)

It was discovered that a heap buffer overflow existed in the Marvell
Wireless LAN device driver for the Linux kernel. An attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2019-10126)

Andrei Vlad Lutas and Dan Lutas discovered that some x86 processors
incorrectly handle SWAPGS instructions during speculative execution. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2019-1125)

It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2019-11833)

It was discovered that the PowerPC dlpar implementation in the Linux kernel
did not properly check for allocation errors in some situations. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2019-12614)

It was discovered that the Linux kernel on ARM processors allowed a tracing
process to modify a syscall after a seccomp decision had been made on that
syscall. A local attacker could possibly use this to bypass seccomp
restrictions. (CVE-2019-2054)

It was discovered that the Marvell Wireless LAN device driver in the Linux
kernel did not properly validate the BSS descriptor. A local attacker could
possibly use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2019-3846)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
linux-image-4.4.0-1050-aws 4.4.0-1050.54
linux-image-4.4.0-159-generic 4.4.0-159.187~14.04.1
linux-image-4.4.0-159-generic-lpae 4.4.0-159.187~14.04.1
linux-image-4.4.0-159-lowlatency 4.4.0-159.187~14.04.1
linux-image-4.4.0-159-powerpc-e500mc 4.4.0-159.187~14.04.1
linux-image-4.4.0-159-powerpc-smp 4.4.0-159.187~14.04.1
linux-image-4.4.0-159-powerpc64-emb 4.4.0-159.187~14.04.1
linux-image-4.4.0-159-powerpc64-smp 4.4.0-159.187~14.04.1
linux-image-aws 4.4.0.1050.51
linux-image-generic-lpae-lts-xenial 4.4.0.159.140
linux-image-generic-lts-xenial 4.4.0.159.140
linux-image-lowlatency-lts-xenial 4.4.0.159.140
linux-image-powerpc-e500mc-lts-xenial 4.4.0.159.140
linux-image-powerpc-smp-lts-xenial 4.4.0.159.140
linux-image-powerpc64-emb-lts-xenial 4.4.0.159.140
linux-image-powerpc64-smp-lts-xenial 4.4.0.159.140
linux-image-virtual-lts-xenial 4.4.0.159.140

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4095-2
https://usn.ubuntu.com/4095-1
CVE-2018-5383, CVE-2019-10126, CVE-2019-1125, CVE-2019-11833,
CVE-2019-12614, CVE-2019-2054, CVE-2019-3846

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl1S7WUACgkQLwmejQBe
gfR2phAAnQ/B6m5inq+27r+60uATXYVArnhpkecPPVO1+/XIuw/YejXbN7Ur8Emu
6yDmkQ1R9wpcHOkaypgJX4cUQExohRSASRkPkYZDxO7104VRf87QXJV0pmZuYDIY
Iv2zBTnwLAJP88ub3f6WVzoiZZ1evv9xWrfm0c+QIhwGB+R+mOGP0G4ZpEnsYLPo
xlG8ZgkyEeT1AbFqBCsF3BWZBEfiE6pUfUDDjIrUIDCkryXbB6z/5+IUrFzGuoT0
6etOPHQe2IVxSUvbCOiUQVtFN4HmGiiWwC5FfW4zYNmUSn9KmkBF07NrVFYzFh29
e9uzvk1Ul+rIBt8zlEdfm8NmjT3gDnLOSZi9nwdTzTj3flHPLZVHe50NmFfP6hAB
BtkTY1ALhUhwHlclUzoSvQuHK99fxe0xPibjqbNyDbWzqz6YPx0BM3TX8pyEUmaW
s5HvVQDUvnURLaFnaBkWi8SsC2/lnd25ZUSc/VQqlVTNZ221O6cFq2ruWgwJvCba
SNEH5c2JjBfp2PV9Gz7wBgOf6GXirMRzROV1PyJHpgbVPrpSS5jFSEop7OPsr52C
lcAfl4oSw/y9jUalBA/a9hQdITMIkJIjsNsBV09cmAz2pAgAe5vYkwUW/dq2Hvr6
7Nfk3J1E4LYcpiUosXfQ/gwRnIfeDLWR7PsT+gS00leC2HjWldU=
=CFsS
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4095-1
August 13, 2019

linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux: Linux kernel
– linux-aws: Linux kernel for Amazon Web Services (AWS) systems
– linux-kvm: Linux kernel for cloud environments
– linux-raspi2: Linux kernel for Raspberry Pi 2
– linux-snapdragon: Linux kernel for Snapdragon processors

Details:

Eli Biham and Lior Neumann discovered that the Bluetooth implementation in
the Linux kernel did not properly validate elliptic curve parameters during
Diffie-Hellman key exchange in some situations. An attacker could use this
to expose sensitive information. (CVE-2018-5383)

It was discovered that a heap buffer overflow existed in the Marvell
Wireless LAN device driver for the Linux kernel. An attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2019-10126)

Andrei Vlad Lutas and Dan Lutas discovered that some x86 processors
incorrectly handle SWAPGS instructions during speculative execution. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2019-1125)

Jann Horn discovered that a race condition existed in the Linux kernel when
performing core dumps. A local attacker could use this to cause a denial of
service (system crash) or expose sensitive information. (CVE-2019-11599)

It was discovered that the PowerPC dlpar implementation in the Linux kernel
did not properly check for allocation errors in some situations. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2019-12614)

Jann Horn discovered that the ptrace implementation in the Linux kernel did
not properly record credentials in some situations. A local attacker could
use this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2019-13272)

It was discovered that the Marvell Wireless LAN device driver in the Linux
kernel did not properly validate the BSS descriptor. A local attacker could
possibly use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2019-3846)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
linux-image-4.4.0-1054-kvm 4.4.0-1054.61
linux-image-4.4.0-1090-aws 4.4.0-1090.101
linux-image-4.4.0-1118-raspi2 4.4.0-1118.127
linux-image-4.4.0-1122-snapdragon 4.4.0-1122.128
linux-image-4.4.0-159-generic 4.4.0-159.187
linux-image-4.4.0-159-generic-lpae 4.4.0-159.187
linux-image-4.4.0-159-lowlatency 4.4.0-159.187
linux-image-4.4.0-159-powerpc-e500mc 4.4.0-159.187
linux-image-4.4.0-159-powerpc-smp 4.4.0-159.187
linux-image-4.4.0-159-powerpc64-emb 4.4.0-159.187
linux-image-4.4.0-159-powerpc64-smp 4.4.0-159.187
linux-image-aws 4.4.0.1090.94
linux-image-generic 4.4.0.159.167
linux-image-generic-lpae 4.4.0.159.167
linux-image-kvm 4.4.0.1054.54
linux-image-lowlatency 4.4.0.159.167
linux-image-powerpc-e500mc 4.4.0.159.167
linux-image-powerpc-smp 4.4.0.159.167
linux-image-powerpc64-emb 4.4.0.159.167
linux-image-powerpc64-smp 4.4.0.159.167
linux-image-raspi2 4.4.0.1118.118
linux-image-snapdragon 4.4.0.1122.114
linux-image-virtual 4.4.0.159.167

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4095-1
CVE-2018-5383, CVE-2019-10126, CVE-2019-1125, CVE-2019-11599,
CVE-2019-12614, CVE-2019-13272, CVE-2019-3846, CVE-2019-9503

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.4.0-159.187
https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1090.101
https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1054.61
https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1118.127
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1122.128

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl1S7U0ACgkQLwmejQBe
gfRRNQ//ZGB07Zcr/ZcIsnZLRNKUTBD5ikPTm5xp2ZzCH+b6xJYa4MgpE/astjUB
hUbUkd2RK60oxlMI3KMYW5LutUK40+pHVSVgn0wDoTKs1V5FCu8Cn7XABM2uuhNx
eh0a5EUt6pT13R8ClXruCv2U/3eFrd9Hb6Mqk5DgvSOjRP9CvEJcOjHps0yk1a8T
EFU2Ku0pJyZYdWIkD1m2Wak0jolMhUiId3p6z5Ri20CrK3ckF3432ctnWad+DhF9
pNgSYmn8vMGUqxh1/ePLDgyHGUHLRYqGg8tUllyQYnKm+NeMZo3YcpBSeb5PeSPo
Gn+A1o91xqTRhEcb3VwV/vcL0NBWO7QUnJBoePn+lPos51vUwR2ocHxcCQUH6zbu
C5MQSysFkU54hcVyqLDhJnMp7N0/F7cw9rBaBqC+VKTLrsYO7c7BmMkmEElBXQ1y
+tBvu6ssO7Yir3DiKLrjrpYmKu8sc7zG+DXxXg0xw8xbjJHVAfCG3iKKBCXdHs+d
4WKGDIsWNlGuGXf4wFSEoEh6gWNaPwIMbn2YxeksXZ4+tUeRkx0V+0E+FDg6lFk9
ICN6ia7Ixn7JpT5506dJ3YMvIWGW5yLwNqFWC7SAEITb2FPNs9WnC3NppwJEVUSe
aMRPQ0s0JN/qfN9nc8jm/YqZYGmHr8Ek3N9NWlrZojjSf2aRB7k=
=RDPc
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4094-1
August 13, 2019

linux, linux-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm,
linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux: Linux kernel
– linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
– linux-gke-4.15: Linux kernel for Google Container Engine (GKE) systems
– linux-kvm: Linux kernel for cloud environments
– linux-oem: Linux kernel for OEM processors
– linux-oracle: Linux kernel for Oracle Cloud systems
– linux-raspi2: Linux kernel for Raspberry Pi 2
– linux-snapdragon: Linux kernel for Snapdragon processors
– linux-azure: Linux kernel for Microsoft Azure Cloud systems
– linux-hwe: Linux hardware enablement (HWE) kernel

Details:

It was discovered that the alarmtimer implementation in the Linux kernel
contained an integer overflow vulnerability. A local attacker could use
this to cause a denial of service. (CVE-2018-13053)

Wen Xu discovered that the XFS filesystem implementation in the Linux
kernel did not properly track inode validations. An attacker could use this
to construct a malicious XFS image that, when mounted, could cause a denial
of service (system crash). (CVE-2018-13093)

Wen Xu discovered that the f2fs file system implementation in the
Linux kernel did not properly validate metadata. An attacker could
use this to construct a malicious f2fs image that, when mounted,
could cause a denial of service (system crash). (CVE-2018-13097,
CVE-2018-13099, CVE-2018-13100, CVE-2018-14614, CVE-2018-14616,
CVE-2018-13096, CVE-2018-13098, CVE-2018-14615)

Wen Xu and Po-Ning Tseng discovered that btrfs file system
implementation in the Linux kernel did not properly validate
metadata. An attacker could use this to construct a malicious
btrfs image that, when mounted, could cause a denial of service
(system crash). (CVE-2018-14610, CVE-2018-14611, CVE-2018-14612,
CVE-2018-14613, CVE-2018-14609)

Wen Xu discovered that the HFS+ filesystem implementation in the Linux
kernel did not properly handle malformed catalog data in some situations.
An attacker could use this to construct a malicious HFS+ image that, when
mounted, could cause a denial of service (system crash). (CVE-2018-14617)

Vasily Averin and Pavel Tikhomirov discovered that the cleancache subsystem
of the Linux kernel did not properly initialize new files in some
situations. A local attacker could use this to expose sensitive
information. (CVE-2018-16862)

Hui Peng and Mathias Payer discovered that the USB subsystem in the Linux
kernel did not properly handle size checks when handling an extra USB
descriptor. A physically proximate attacker could use this to cause a
denial of service (system crash). (CVE-2018-20169)

It was discovered that a use-after-free error existed in the block layer
subsystem of the Linux kernel when certain failure conditions occurred. A
local attacker could possibly use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2018-20856)

Eli Biham and Lior Neumann discovered that the Bluetooth implementation in
the Linux kernel did not properly validate elliptic curve parameters during
Diffie-Hellman key exchange in some situations. An attacker could use this
to expose sensitive information. (CVE-2018-5383)

It was discovered that a heap buffer overflow existed in the Marvell
Wireless LAN device driver for the Linux kernel. An attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2019-10126)

Andrei Vlad Lutas and Dan Lutas discovered that some x86 processors
incorrectly handle SWAPGS instructions during speculative execution. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2019-1125)

It was discovered that the PowerPC dlpar implementation in the Linux kernel
did not properly check for allocation errors in some situations. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2019-12614)

It was discovered that a NULL pointer dereference vulnerabilty existed in
the Near-field communication (NFC) implementation in the Linux kernel. An
attacker could use this to cause a denial of service (system crash).
(CVE-2019-12818)

It was discovered that the MDIO bus devices subsystem in the Linux kernel
improperly dropped a device reference in an error condition, leading to a
use-after-free. An attacker could use this to cause a denial of service
(system crash). (CVE-2019-12819)

It was discovered that a NULL pointer dereference vulnerability existed in
the Near-field communication (NFC) implementation in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2019-12984)

Jann Horn discovered a use-after-free vulnerability in the Linux kernel
when accessing LDT entries in some situations. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2019-13233)

Jann Horn discovered that the ptrace implementation in the Linux kernel did
not properly record credentials in some situations. A local attacker could
use this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2019-13272)

It was discovered that the Empia EM28xx DVB USB device driver
implementation in the Linux kernel contained a use-after-free vulnerability
when disconnecting the device. An attacker could use this to cause a denial
of service (system crash). (CVE-2019-2024)

It was discovered that the USB video device class implementation in the
Linux kernel did not properly validate control bits, resulting in an out of
bounds buffer read. A local attacker could use this to possibly expose
sensitive information (kernel memory). (CVE-2019-2101)

It was discovered that the Marvell Wireless LAN device driver in the Linux
kernel did not properly validate the BSS descriptor. A local attacker could
possibly use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2019-3846)

It was discovered that the Appletalk IP encapsulation driver in the Linux
kernel did not properly prevent kernel addresses from being copied to user
space. A local attacker with the CAP_NET_ADMIN capability could use this to
expose sensitive information. (CVE-2018-20511)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
linux-image-4.15.0-1021-oracle 4.15.0-1021.23
linux-image-4.15.0-1040-gcp 4.15.0-1040.42
linux-image-4.15.0-1040-gke 4.15.0-1040.42
linux-image-4.15.0-1042-kvm 4.15.0-1042.42
linux-image-4.15.0-1043-raspi2 4.15.0-1043.46
linux-image-4.15.0-1050-oem 4.15.0-1050.57
linux-image-4.15.0-1060-snapdragon 4.15.0-1060.66
linux-image-4.15.0-58-generic 4.15.0-58.64
linux-image-4.15.0-58-generic-lpae 4.15.0-58.64
linux-image-4.15.0-58-lowlatency 4.15.0-58.64
linux-image-gcp 4.15.0.1040.42
linux-image-generic 4.15.0.58.60
linux-image-generic-lpae 4.15.0.58.60
linux-image-gke 4.15.0.1040.43
linux-image-gke-4.15 4.15.0.1040.43
linux-image-kvm 4.15.0.1042.42
linux-image-lowlatency 4.15.0.58.60
linux-image-oem 4.15.0.1050.54
linux-image-oracle 4.15.0.1021.24
linux-image-powerpc-e500mc 4.15.0.58.60
linux-image-powerpc-smp 4.15.0.58.60
linux-image-powerpc64-emb 4.15.0.58.60
linux-image-powerpc64-smp 4.15.0.58.60
linux-image-raspi2 4.15.0.1043.41
linux-image-snapdragon 4.15.0.1060.63
linux-image-virtual 4.15.0.58.60

Ubuntu 16.04 LTS:
linux-image-4.15.0-1021-oracle 4.15.0-1021.23~16.04.1
linux-image-4.15.0-1040-gcp 4.15.0-1040.42~16.04.1
linux-image-4.15.0-1055-azure 4.15.0-1055.60
linux-image-4.15.0-58-generic 4.15.0-58.64~16.04.1
linux-image-4.15.0-58-generic-lpae 4.15.0-58.64~16.04.1
linux-image-4.15.0-58-lowlatency 4.15.0-58.64~16.04.1
linux-image-azure 4.15.0.1055.58
linux-image-gcp 4.15.0.1040.54
linux-image-generic-hwe-16.04 4.15.0.58.79
linux-image-generic-lpae-hwe-16.04 4.15.0.58.79
linux-image-gke 4.15.0.1040.54
linux-image-lowlatency-hwe-16.04 4.15.0.58.79
linux-image-oem 4.15.0.58.79
linux-image-oracle 4.15.0.1021.15
linux-image-virtual-hwe-16.04 4.15.0.58.79

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4094-1
CVE-2018-13053, CVE-2018-13093, CVE-2018-13096, CVE-2018-13097,
CVE-2018-13098, CVE-2018-13099, CVE-2018-13100, CVE-2018-14609,
CVE-2018-14610, CVE-2018-14611, CVE-2018-14612, CVE-2018-14613,
CVE-2018-14614, CVE-2018-14615, CVE-2018-14616, CVE-2018-14617,
CVE-2018-16862, CVE-2018-20169, CVE-2018-20511, CVE-2018-20856,
CVE-2018-5383, CVE-2019-10126, CVE-2019-1125, CVE-2019-12614,
CVE-2019-12818, CVE-2019-12819, CVE-2019-12984, CVE-2019-13233,
CVE-2019-13272, CVE-2019-2024, CVE-2019-2101, CVE-2019-3846

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.15.0-58.64
https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1040.42
https://launchpad.net/ubuntu/+source/linux-gke-4.15/4.15.0-1040.42
https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1042.42
https://launchpad.net/ubuntu/+source/linux-oem/4.15.0-1050.57
https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1021.23
https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1043.46
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1060.66
https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1055.60
https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1040.42~16.04.1
https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-58.64~16.04.1
https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1021.23~16.04.1

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl1S7UEACgkQLwmejQBe
gfT1uQ//UnlFOks02No/TIrgDKC8TJ/iYPsxejrJwLbbT1cVpRJE1iNwUL6wDALP
5WSQOJZbjoA6ArWPykHjx389j8eW+D3pOl8pz9QUjNr0AG02RumokNGb6aBUgt+8
6tYY+w7xAlWf17sV1cmL7YpTRn29vGyz/G0SsWKx+hZQILepasfrzOqsNE/SKKQt
1zRcsr0kc0D2FYlJ+IkE81mtQnIkrA7gubNhbel3ksZpkCtT6EIAOhgd4hCoJpFh
wTnrcU40wLPpnhy9FxKwypY1zo9Gz9hkboNYuC5ZnBGQrvQKj3dm63hpfpU5+New
+B2rb2hNpkfrzXOkA80LStKpWvc6Q+9rAIQXFnSv5HamOP2+ljnWJNCPIoEs6/OQ
h47rMgh3FptFUNtc+8gm1OY6In8m1v56+MngwQS7aLuMLn5VB3jOHIgjavMNcYPr
ntEWevuH22qJ3hyCmb6CcHPyWwHmUTJBCAfPvAsG5lzYlV5uoRrggOmCnE3UJZuX
oUoEy0nQ9jgpqTykVQtY8UAjVQSn57E4z4b0a48apmvAqNgrHnVtkurZ6tKPTc2F
+VO1+HF9LG4s7hYrv/QfVz3A8qZJs05y9okihnHqMsVVBH+M16WnUhBmJJVF6Igb
TxoxXKmtpu4vjBUn58Yx5739uHEy26qaUFoFgVMUa3nRsUF38oA=
=VB0E
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4093-1
August 13, 2019

linux, linux-hwe, linux-azure, linux-gcp, linux-kvm, linux-raspi2,
linux-snapdragon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.04
– Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux: Linux kernel
– linux-azure: Linux kernel for Microsoft Azure Cloud systems
– linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
– linux-kvm: Linux kernel for cloud environments
– linux-raspi2: Linux kernel for Raspberry Pi 2
– linux-snapdragon: Linux kernel for Snapdragon processors
– linux-hwe: Linux hardware enablement (HWE) kernel

Details:

It was discovered that a heap buffer overflow existed in the Marvell
Wireless LAN device driver for the Linux kernel. An attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2019-10126)

Andrei Vlad Lutas and Dan Lutas discovered that some x86 processors
incorrectly handle SWAPGS instructions during speculative execution. A
local attacker could use this to expose sensitive information (kernel
memory). (CVE-2019-1125)

It was discovered that the PowerPC dlpar implementation in the Linux kernel
did not properly check for allocation errors in some situations. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2019-12614)

It was discovered that a NULL pointer dereference vulnerability existed in
the Near-field communication (NFC) implementation in the Linux kernel. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2019-12984)

Jann Horn discovered a use-after-free vulnerability in the Linux kernel
when accessing LDT entries in some situations. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2019-13233)

Jann Horn discovered that the ptrace implementation in the Linux kernel did
not properly record credentials in some situations. A local attacker could
use this to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2019-13272)

It was discovered that the Marvell Wireless LAN device driver in the Linux
kernel did not properly validate the BSS descriptor. A local attacker could
possibly use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2019-3846)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
linux-image-5.0.0-1013-gcp 5.0.0-1013.13
linux-image-5.0.0-1013-kvm 5.0.0-1013.14
linux-image-5.0.0-1014-azure 5.0.0-1014.14
linux-image-5.0.0-1014-raspi2 5.0.0-1014.14
linux-image-5.0.0-1018-snapdragon 5.0.0-1018.19
linux-image-5.0.0-25-generic 5.0.0-25.26
linux-image-5.0.0-25-generic-lpae 5.0.0-25.26
linux-image-5.0.0-25-lowlatency 5.0.0-25.26
linux-image-azure 5.0.0.1014.13
linux-image-gcp 5.0.0.1013.13
linux-image-generic 5.0.0.25.26
linux-image-generic-lpae 5.0.0.25.26
linux-image-gke 5.0.0.1013.13
linux-image-kvm 5.0.0.1013.13
linux-image-lowlatency 5.0.0.25.26
linux-image-raspi2 5.0.0.1014.11
linux-image-snapdragon 5.0.0.1018.11
linux-image-virtual 5.0.0.25.26

Ubuntu 18.04 LTS:
linux-image-5.0.0-1014-azure 5.0.0-1014.14~18.04.1
linux-image-5.0.0-25-generic 5.0.0-25.26~18.04.1
linux-image-5.0.0-25-generic-lpae 5.0.0-25.26~18.04.1
linux-image-5.0.0-25-lowlatency 5.0.0-25.26~18.04.1
linux-image-azure 5.0.0.1014.25
linux-image-generic-hwe-18.04 5.0.0.25.82
linux-image-generic-lpae-hwe-18.04 5.0.0.25.82
linux-image-lowlatency-hwe-18.04 5.0.0.25.82
linux-image-snapdragon-hwe-18.04 5.0.0.25.82
linux-image-virtual-hwe-18.04 5.0.0.25.82

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4093-1
CVE-2019-10126, CVE-2019-1125, CVE-2019-12614, CVE-2019-12984,
CVE-2019-13233, CVE-2019-13272, CVE-2019-3846

Package Information:
https://launchpad.net/ubuntu/+source/linux/5.0.0-25.26
https://launchpad.net/ubuntu/+source/linux-azure/5.0.0-1014.14
https://launchpad.net/ubuntu/+source/linux-gcp/5.0.0-1013.13
https://launchpad.net/ubuntu/+source/linux-kvm/5.0.0-1013.14
https://launchpad.net/ubuntu/+source/linux-raspi2/5.0.0-1014.14
https://launchpad.net/ubuntu/+source/linux-snapdragon/5.0.0-1018.19
https://launchpad.net/ubuntu/+source/linux-azure/5.0.0-1014.14~18.04.1
https://launchpad.net/ubuntu/+source/linux-hwe/5.0.0-25.26~18.04.1

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl1S7PMACgkQLwmejQBe
gfRZ/g/9ER9hShVhKaBM1/ZftB9Dnepc0X8rn8AMn3P2Bb/W7fBclAxuL6snI4pI
mBRX8gArAxe+Vt/dFnm2gyQ+lu9RnO+fS917w85tRb1RiLuaOxoqEYs84EQyAIOR
zcqKCJaVRDXv4XOXS42mHe5nS+TRUiBxhrmdbOkHxyUA6dCLr4r8iMSWoohaA1L9
RY9GFZFPJDM2NZoK9qlAHOy5KmtAZ39D92d+nnDFMl+CxPTctvdRpAcT2TR5ENiJ
N/AqvzNWlsFrbRf+47NZNBQwZkiLpnQgfLtQR6+IVhFegyL7A59yfyXt/7qwvzvc
fMic4Qz+eXFpRXfFJfHXS9xSFR2plNL1+TS803i/7maAenR98YfZfq96fN9gV+29
uULQeBt9idaLG+ZhwGBEhjpfEU3X5V572VQBEbx3tIa63NoFaxpLqFO1n2FVVxYj
31VXNjhfk8wyPouqjlgh7ejeXX/lNjGStP4XO3Qw7fOWh3xc8hsC5dvTCSqCRduA
pFp8lRcO1RMKSwnADJujjahff2L/umZbrOTUPHW/uv5cQUiSq97+jo2CJeZ/iE8y
nyoo4xdiEjwTJ6wW9iARe22Yf5Oiq+0CiQkbCCUUf8vM7pwCz+3l81r75ppYuP+5
R77Ha4XZl1+ToqwaqZcHjL1y/5DImtXMh6g5e5doSxCNfUmbmFI=
=lF78
—–END PGP SIGNATURE—–

AutorToni Vugdelija
Cert idNCERT-REF-2019-08-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa jhead

Otkriveni su sigurnosni nedostaci u programskom paketu jhead za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja....

Close