You are here
Home > Preporuke > Sigurnosni nedostaci jezgre operacijskog sustava

Sigurnosni nedostaci jezgre operacijskog sustava

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4576-1
October 14, 2020

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp,
linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4,
linux-raspi, linux-raspi-5.4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 20.04 LTS
– Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux: Linux kernel
– linux-aws: Linux kernel for Amazon Web Services (AWS) systems
– linux-azure: Linux kernel for Microsoft Azure Cloud systems
– linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
– linux-kvm: Linux kernel for cloud environments
– linux-oracle: Linux kernel for Oracle Cloud systems
– linux-raspi: Linux kernel for Raspberry Pi (V8) systems
– linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems
– linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems
– linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems
– linux-hwe-5.4: Linux hardware enablement (HWE) kernel
– linux-oracle-5.4: Linux kernel for Oracle Cloud systems
– linux-raspi-5.4: Linux kernel for Raspberry Pi (V8) systems

Details:

Hador Manor discovered that the DCCP protocol implementation in the Linux
kernel improperly handled socket reuse, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-16119)

Jay Shin discovered that the ext4 file system implementation in the Linux
kernel did not properly handle directory access with broken indexing,
leading to an out-of-bounds read vulnerability. A local attacker could use
this to cause a denial of service (system crash). (CVE-2020-14314)

David Alan Gilbert discovered that the XFS file system implementation in
the Linux kernel did not properly perform metadata validation in some
circumstances. A local attacker could use this to cause a denial of
service. (CVE-2020-14385)

Giuseppe Scrivano discovered that the overlay file system in the Linux
kernel did not properly perform permission checks in some situations. A
local attacker could possibly use this to bypass intended restrictions and
gain read access to restricted files. (CVE-2020-16120)

It was discovered that a race condition existed in the hugetlb sysctl
implementation in the Linux kernel. A privileged attacker could use this to
cause a denial of service (system crash). (CVE-2020-25285)

It was discovered that the block layer subsystem in the Linux kernel did
not properly handle zero-length requests. A local attacker could use this
to cause a denial of service. (CVE-2020-25641)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
linux-image-5.4.0-1021-raspi 5.4.0-1021.24
linux-image-5.4.0-1026-kvm 5.4.0-1026.27
linux-image-5.4.0-1028-aws 5.4.0-1028.29
linux-image-5.4.0-1028-gcp 5.4.0-1028.29
linux-image-5.4.0-1028-oracle 5.4.0-1028.29
linux-image-5.4.0-1031-azure 5.4.0-1031.32
linux-image-5.4.0-51-generic 5.4.0-51.56
linux-image-5.4.0-51-generic-lpae 5.4.0-51.56
linux-image-5.4.0-51-lowlatency 5.4.0-51.56
linux-image-aws 5.4.0.1028.29
linux-image-azure 5.4.0.1031.29
linux-image-gcp 5.4.0.1028.36
linux-image-generic 5.4.0.51.54
linux-image-generic-hwe-20.04 5.4.0.51.54
linux-image-generic-lpae 5.4.0.51.54
linux-image-generic-lpae-hwe-20.04 5.4.0.51.54
linux-image-gke 5.4.0.1028.36
linux-image-kvm 5.4.0.1026.24
linux-image-lowlatency 5.4.0.51.54
linux-image-lowlatency-hwe-20.04 5.4.0.51.54
linux-image-oem 5.4.0.51.54
linux-image-oem-osp1 5.4.0.51.54
linux-image-oracle 5.4.0.1028.25
linux-image-raspi 5.4.0.1021.56
linux-image-raspi2 5.4.0.1021.56
linux-image-virtual 5.4.0.51.54
linux-image-virtual-hwe-20.04 5.4.0.51.54

Ubuntu 18.04 LTS:
linux-image-5.4.0-1021-raspi 5.4.0-1021.24~18.04.1
linux-image-5.4.0-1028-aws 5.4.0-1028.29~18.04.1
linux-image-5.4.0-1028-gcp 5.4.0-1028.29~18.04.1
linux-image-5.4.0-1028-oracle 5.4.0-1028.29~18.04.1
linux-image-5.4.0-1031-azure 5.4.0-1031.32~18.04.1
linux-image-5.4.0-51-generic 5.4.0-51.56~18.04.1
linux-image-5.4.0-51-generic-lpae 5.4.0-51.56~18.04.1
linux-image-5.4.0-51-lowlatency 5.4.0-51.56~18.04.1
linux-image-aws 5.4.0.1028.13
linux-image-azure 5.4.0.1031.13
linux-image-gcp 5.4.0.1028.16
linux-image-generic-hwe-18.04 5.4.0.51.56~18.04.45
linux-image-generic-lpae-hwe-18.04 5.4.0.51.56~18.04.45
linux-image-lowlatency-hwe-18.04 5.4.0.51.56~18.04.45
linux-image-oracle 5.4.0.1028.12
linux-image-raspi-hwe-18.04 5.4.0.1021.25
linux-image-snapdragon-hwe-18.04 5.4.0.51.56~18.04.45
linux-image-virtual-hwe-18.04 5.4.0.51.56~18.04.45

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4576-1
CVE-2020-14314, CVE-2020-14385, CVE-2020-16119, CVE-2020-16120,
CVE-2020-25285, CVE-2020-25641

Package Information:
https://launchpad.net/ubuntu/+source/linux/5.4.0-51.56
https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1028.29
https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1031.32
https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1028.29
https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1026.27
https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1028.29
https://launchpad.net/ubuntu/+source/linux-raspi/5.4.0-1021.24
https://launchpad.net/ubuntu/+source/linux-aws-5.4/5.4.0-1028.29~18.04.1
https://launchpad.net/ubuntu/+source/linux-azure-5.4/5.4.0-1031.32~18.04.1
https://launchpad.net/ubuntu/+source/linux-gcp-5.4/5.4.0-1028.29~18.04.1
https://launchpad.net/ubuntu/+source/linux-hwe-5.4/5.4.0-51.56~18.04.1
https://launchpad.net/ubuntu/+source/linux-oracle-5.4/5.4.0-1028.29~18.04.1
https://launchpad.net/ubuntu/+source/linux-raspi-5.4/5.4.0-1021.24~18.04.1

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl+GYxMACgkQLwmejQBe
gfRsXQ//foXdFRR6jdkjCiEjIubEhmw9UFBGjBjdaMm+bvjapT/6VHke2ZZ+w8TL
lclKcvDBm7tC4+zU4vVFOYC8St85mOqityouwePrAJNMIFEzIarkqlHeeiZd/SaH
XsIJeKKc024mGrCSP+oPDPm79G9bnzskztkHIpHEzsYK05yODcfxSYPa8zVaojke
KriklwFeSr/I6nBMJviELknXM/9dChwqEIpiPdRetrWoAtNu4paW1GxoVj952gnD
0bF8pBUQ1CEeWvo1QdyffkmIYvS1EXO0xqY7qR91DTfLxD57ZHHsfNRMl+6rORnV
4/QfF20D17mo85NrFRSkjtwD5+ylBkJYiIJ1IqfSa4iPuEwTHHidcJw0KkmushUX
YNdCiFk2fPU1hDrAXDtoF1xMBBe4TReRsJLFegf21K9ez706GQI5+uWiH5pkbCWo
4wSq0r6p2ek8hMWngPjfkFEpEIWZYBp2xmZKjchFZvZPEhJTLO/dssatysR8AFOt
bTYufzbgH5rZGFGpY0IFSPdSGMx+YPwUeDdH3bYxU57JvPWXqUVfOasAs4Yx2PtT
vWDyn0pM+ldSaJWMlPCGi9yu2h35efl+oeIV44cVIIS62p/KplxJujIhGtxh7bmh
DfYq2vKM5v1A5wrGsaRz8cCLle4aXIDWXggX68hI4oKRBz3mXkA=
=iNKS
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4577-1
October 14, 2020

linux-hwe, linux-gke-5.0, linux-gke-5.3, linux-oem-osp1, linux-raspi2-5.3
vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux-gke-5.0: Linux kernel for Google Container Engine (GKE) systems
– linux-gke-5.3: Linux kernel for Google Container Engine (GKE) systems
– linux-hwe: Linux hardware enablement (HWE) kernel
– linux-oem-osp1: Linux kernel for OEM systems
– linux-raspi2-5.3: Linux kernel for Raspberry Pi (V8) systems

Details:

Hador Manor discovered that the DCCP protocol implementation in the Linux
kernel improperly handled socket reuse, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-16119)

Giuseppe Scrivano discovered that the overlay file system in the Linux
kernel did not properly perform permission checks in some situations. A
local attacker could possibly use this to bypass intended restrictions and
gain read access to restricted files. (CVE-2020-16120)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
linux-image-5.0.0-1049-gke 5.0.0-1049.50
linux-image-5.0.0-1069-oem-osp1 5.0.0-1069.75
linux-image-5.3.0-1035-raspi2 5.3.0-1035.37
linux-image-5.3.0-1038-gke 5.3.0-1038.40
linux-image-5.3.0-68-generic 5.3.0-68.63
linux-image-5.3.0-68-lowlatency 5.3.0-68.63
linux-image-gke-5.0 5.0.0.1049.33
linux-image-gke-5.3 5.3.0.1038.21
linux-image-gkeop-5.3 5.3.0.68.125
linux-image-oem-osp1 5.0.0.1069.67
linux-image-raspi2-hwe-18.04 5.3.0.1035.24

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4577-1
CVE-2020-16119, CVE-2020-16120

Package Information:
https://launchpad.net/ubuntu/+source/linux-gke-5.0/5.0.0-1049.50
https://launchpad.net/ubuntu/+source/linux-gke-5.3/5.3.0-1038.40
https://launchpad.net/ubuntu/+source/linux-hwe/5.3.0-68.63
https://launchpad.net/ubuntu/+source/linux-oem-osp1/5.0.0-1069.75
https://launchpad.net/ubuntu/+source/linux-raspi2-5.3/5.3.0-1035.37

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl+GYyMACgkQLwmejQBe
gfQBIhAAo8ms7iPsfKmKf1MwWz4/KDfqHg3scwvEPV2PNl0IgybYlHbZfKcSmAjP
qroLcFaSXGbVoaTj9Np7kn4C1GYg10hVF9w7CBCFYw2JPW02aSJm29WbuFABjTkx
rkHG/QlWwiV7h8gYqkY2u9um+EDfse0EdsLpEgTVaqEy/zVaYGEliHsO19qRdIgk
eQX3/8pmCPzxKa2xw4qpsTx6xAa3n5vdO3l88RXU0F2452kOkekUXccHR1721Qkb
pVUPOpLalsbKy0GAMqjQzkQ3ubH6nN5qPeaIFrTrOWkYAECygJBML7KdUlBE/96E
7uCw4AaSPKNT4NK8QonhV1Sd7+fncljyYuWEx8/OQVCOLZcFTjgkqmlxooCu5kN4
HTDiwbEiZXrF7f2wixS7lqvyEdLSoQPluu99Ium9QfURKYXng8b6r7H2R/cshZj4
V5AspUtl1Qeh6+8jFkHcmpwS0bOh+85TXRj8uTiMQR1SO067sRJBWkdTAE+aNwS+
7RnfUNL5yab+q2fxzNhT43ZeKuZpqzeugNqnS9lFbleRBWjZk3GYh+K2tcQote51
gJx+7AMobBHIHP14thiWXYTUyEK+nsU8HqEJ4rKdb9fLYaow8uQvCq2/nDS0y2I5
NSfCDbcaNf2Y4NyL0py2RJ2uLz2XRAbjioJVswa/Y5MqtUZC5Ps=
=y+yW
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4578-1
October 14, 2020

linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp,
linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem,
linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
– Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux: Linux kernel
– linux-aws: Linux kernel for Amazon Web Services (AWS) systems
– linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems
– linux-gcp-4.15: Linux kernel for Google Cloud Platform (GCP) systems
– linux-gke-4.15: Linux kernel for Google Container Engine (GKE) systems
– linux-kvm: Linux kernel for cloud environments
– linux-oem: Linux kernel for OEM systems
– linux-oracle: Linux kernel for Oracle Cloud systems
– linux-raspi2: Linux kernel for Raspberry Pi (V8) systems
– linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors
– linux-aws-hwe: Linux kernel for Amazon Web Services (AWS-HWE) systems
– linux-azure: Linux kernel for Microsoft Azure Cloud systems
– linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
– linux-hwe: Linux hardware enablement (HWE) kernel

Details:

Hador Manor discovered that the DCCP protocol implementation in the Linux
kernel improperly handled socket reuse, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-16119)

Wen Xu discovered that the XFS file system in the Linux kernel did not
properly validate inode metadata in some situations. An attacker could use
this to construct a malicious XFS image that, when mounted, could cause a
denial of service (system crash). (CVE-2018-10322)

It was discovered that the btrfs file system in the Linux kernel contained
a use-after-free vulnerability when merging free space. An attacker could
use this to construct a malicious btrfs image that, when mounted and
operated on, could cause a denial of service (system crash).
(CVE-2019-19448)

Jay Shin discovered that the ext4 file system implementation in the Linux
kernel did not properly handle directory access with broken indexing,
leading to an out-of-bounds read vulnerability. A local attacker could use
this to cause a denial of service (system crash). (CVE-2020-14314)

Giuseppe Scrivano discovered that the overlay file system in the Linux
kernel did not properly perform permission checks in some situations. A
local attacker could possibly use this to bypass intended restrictions and
gain read access to restricted files. (CVE-2020-16120)

It was discovered that the NFS client implementation in the Linux kernel
did not properly perform bounds checking before copying security labels in
some situations. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code. (CVE-2020-25212)

It was discovered that the NFC implementation in the Linux kernel did not
properly perform permissions checks when opening raw sockets. A local
attacker could use this to create or listen to NFC traffic.
(CVE-2020-26088)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
linux-image-4.15.0-1057-oracle 4.15.0-1057.62
linux-image-4.15.0-1072-gke 4.15.0-1072.76
linux-image-4.15.0-1073-raspi2 4.15.0-1073.78
linux-image-4.15.0-1077-kvm 4.15.0-1077.79
linux-image-4.15.0-1086-aws 4.15.0-1086.91
linux-image-4.15.0-1086-gcp 4.15.0-1086.98
linux-image-4.15.0-1089-snapdragon 4.15.0-1089.98
linux-image-4.15.0-1099-azure 4.15.0-1099.110
linux-image-4.15.0-1099-oem 4.15.0-1099.109
linux-image-4.15.0-121-generic 4.15.0-121.123
linux-image-4.15.0-121-generic-lpae 4.15.0-121.123
linux-image-4.15.0-121-lowlatency 4.15.0-121.123
linux-image-aws-lts-18.04 4.15.0.1086.88
linux-image-azure-lts-18.04 4.15.0.1099.72
linux-image-gcp-lts-18.04 4.15.0.1086.104
linux-image-generic 4.15.0.121.108
linux-image-generic-lpae 4.15.0.121.108
linux-image-gke 4.15.0.1072.76
linux-image-gke-4.15 4.15.0.1072.76
linux-image-kvm 4.15.0.1077.73
linux-image-lowlatency 4.15.0.121.108
linux-image-oem 4.15.0.1099.103
linux-image-oracle-lts-18.04 4.15.0.1057.67
linux-image-powerpc-e500mc 4.15.0.121.108
linux-image-powerpc-smp 4.15.0.121.108
linux-image-powerpc64-emb 4.15.0.121.108
linux-image-powerpc64-smp 4.15.0.121.108
linux-image-raspi2 4.15.0.1073.70
linux-image-snapdragon 4.15.0.1089.92
linux-image-virtual 4.15.0.121.108

Ubuntu 16.04 LTS:
linux-image-4.15.0-1056-oracle 4.15.0-1056.61~16.04.1
linux-image-4.15.0-1085-aws 4.15.0-1085.90~16.04.1
linux-image-4.15.0-1086-gcp 4.15.0-1086.98~16.04.1
linux-image-4.15.0-1098-azure 4.15.0-1098.109~16.04.1
linux-image-4.15.0-120-generic 4.15.0-120.122~16.04.1
linux-image-4.15.0-120-generic-lpae 4.15.0-120.122~16.04.1
linux-image-4.15.0-120-lowlatency 4.15.0-120.122~16.04.1
linux-image-aws-hwe 4.15.0.1085.81
linux-image-azure 4.15.0.1098.92
linux-image-gcp 4.15.0.1086.87
linux-image-generic-hwe-16.04 4.15.0.120.121
linux-image-generic-lpae-hwe-16.04 4.15.0.120.121
linux-image-gke 4.15.0.1086.87
linux-image-lowlatency-hwe-16.04 4.15.0.120.121
linux-image-oem 4.15.0.120.121
linux-image-oracle 4.15.0.1056.46
linux-image-virtual-hwe-16.04 4.15.0.120.121

Ubuntu 14.04 ESM:
linux-image-4.15.0-1098-azure 4.15.0-1098.109~14.04.1
linux-image-azure 4.15.0.1098.74

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4578-1
CVE-2018-10322, CVE-2019-19448, CVE-2020-14314, CVE-2020-16119,
CVE-2020-16120, CVE-2020-25212, CVE-2020-26088

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.15.0-121.123
https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1086.91
https://launchpad.net/ubuntu/+source/linux-azure-4.15/4.15.0-1099.110
https://launchpad.net/ubuntu/+source/linux-gcp-4.15/4.15.0-1086.98
https://launchpad.net/ubuntu/+source/linux-gke-4.15/4.15.0-1072.76
https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1077.79
https://launchpad.net/ubuntu/+source/linux-oem/4.15.0-1099.109
https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1057.62
https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1073.78
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1089.98
https://launchpad.net/ubuntu/+source/linux-aws-hwe/4.15.0-1085.90~16.04.1
https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1098.109~16.04.1
https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1086.98~16.04.1
https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-120.122~16.04.1
https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1056.61~16.04.1

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl+GYy4ACgkQLwmejQBe
gfRpJxAAgyFLCTrUDqCPsDUN9uszpSGLI7GjtWYdIW1zPhG4xaMSTmptKSo/BdnF
NN83dN8sBJl/aTEqj7jFCCj22eC7nI36Gtgn5DpzGCGKiYjxjbt0n/GLJY9FwQYy
sW9e/Rv+/TVUR6FsHYkc4aUyuKUCry6zClLxtFF4U6Xt2vVJO8n9G5enuOqlyZDx
1o9Q9+b23VPnJDRIb1l71Ga71DZFC0NefliXCJJh7R/evBfIFv6N3KcG9OKGKxJg
s+P3z4i5o5XedLzSbALI7vf8+dV81OmNMPatFDkmiVZiX49N3zHDOZdiVRJl1Npv
paI4yswOoQnQ35n45By0LK0/M43veIov0620te6ovxpxY3sbHM3u9MS5MYCu2RIc
l3SL7gkAj7GIr3NIqm5m/4sWr7g4yShWYEzIpXPRePBMjUIJLvPYsZ0ndMIEUUBh
e4u/aCGY8aLC3bm0xWx9eqCSoUNdL6tZrKWjdF0exHEm20BsQTUoVtmYblRSkEyC
qRgu//oOk7ybmQAmDlvTL8xDmeYjFR89PvxE8dwsEXocdKjd5ETLbJK5/VJb4ofT
HD3PnipzEtslQzGCsbWq6DYBjw/ts9KF6nU8dq8+CE6YU1QvCt1Sw9V2ywl65cIl
eTnM54baf/Z/VnDjZfLxrdOTJQpu51zZV1QY05rM6GvoFQj1MiQ=
=WoA2
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4580-1
October 14, 2020

linux, linux-lts-trusty vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 ESM
– Ubuntu 12.04 ESM

Summary:

The system could be made to crash or possibly run programs as an
administrator.

Software Description:
– linux: Linux kernel
– linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise ESM

Details:

Hador Manor discovered that the DCCP protocol implementation in the Linux
kernel improperly handled socket reuse, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
linux-image-3.13.0-182-generic 3.13.0-182.233
linux-image-3.13.0-182-generic-lpae 3.13.0-182.233
linux-image-3.13.0-182-lowlatency 3.13.0-182.233
linux-image-generic 3.13.0.182.191
linux-image-generic-lpae 3.13.0.182.191
linux-image-generic-pae 3.13.0.182.191
linux-image-highbank 3.13.0.182.191
linux-image-lowlatency 3.13.0.182.191
linux-image-lowlatency-pae 3.13.0.182.191
linux-image-omap 3.13.0.182.191
linux-image-server 3.13.0.182.191
linux-image-virtual 3.13.0.182.191

Ubuntu 12.04 ESM:
linux-image-3.13.0-182-generic 3.13.0-182.233~12.04.1
linux-image-3.13.0-182-generic-lpae 3.13.0-182.233~12.04.1
linux-image-3.13.0-182-lowlatency 3.13.0-182.233~12.04.1
linux-image-3.2.0-149-generic 3.2.0-149.196
linux-image-3.2.0-149-generic-pae 3.2.0-149.196
linux-image-3.2.0-149-highbank 3.2.0-149.196
linux-image-3.2.0-149-omap 3.2.0-149.196
linux-image-3.2.0-149-virtual 3.2.0-149.196
linux-image-generic 3.2.0.149.163
linux-image-generic-lpae-lts-trusty 3.13.0.182.168
linux-image-generic-lts-trusty 3.13.0.182.168
linux-image-generic-pae 3.2.0.149.163
linux-image-highbank 3.2.0.149.163
linux-image-server 3.2.0.149.163
linux-image-virtual 3.2.0.149.163

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4580-1
CVE-2020-16119

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl+GY0IACgkQLwmejQBe
gfQ72g//dXtr3/BhIeqgkZiYiLHtgiTtwlDyqQhZC+2XcFMMpLdQhzRrMruE/a0v
2nrHcyIqHTyYVYk1lo5SGg2vOmNe3rFjNbVW+P4NBHLnAHAtm17Ll5JcuP+9/3uC
HocOcAjrT28Tq+vAZC6DOews2Nweuftt4f3Y2aH4X9KdDIAipFkwB2lj6DZN/wer
nh0UMiwvitauZzK/Myuez4O5l1FlcgKGYT+3QZ+TEIvJ5A0RWy1mlH+M3/oOJQjP
TRV/jw874wf1phVU0r3B5VaHDNFWUP4PM4msZNGGDwBc9S+q8fP+uaclxH3zX8sa
zA+2mtq7YHhSBP0vXM1HNj4GgdBK56LyzpvCQnCoQjVVp0iQx+y6CCoRrl2yW1dT
inVG8tGBsecUqPGznvvzYHFQkbW6aBZFVJYqi5Pn20bBWfx0l/d5pZrK+h0Ol++i
myrN1QHWp+V1e/xPEqxfKXBVu2j0GOl9dp0gD3TWOGbqP+ZSpAEcLpufE4G+Ynoh
Xs03/vqjhmAPwuhYILYRp33PyEvnw9Hg3dzZintf9jGNMruUjAYM3OpXbfQpMCJ8
d5cnXDlWvt4sr9Ddp0mpa3XZ0KgnZVWGNvRc5ATgD+j4oJGx3ctxV0jE7wZrpbNW
fhMrP9bQO7Im2F4ZGkQl2ULdkv0LB4mP6vZQIifgf3BBKvEmzcs=
=6Ygb
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-4579-1
October 14, 2020

linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi2,
linux-snapdragon vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.04 LTS
– Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux: Linux kernel
– linux-aws: Linux kernel for Amazon Web Services (AWS) systems
– linux-kvm: Linux kernel for cloud environments
– linux-raspi2: Linux kernel for Raspberry Pi (V8) systems
– linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors
– linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty

Details:

Hador Manor discovered that the DCCP protocol implementation in the Linux
kernel improperly handled socket reuse, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-16119)

Wen Xu discovered that the XFS file system in the Linux kernel did not
properly validate inode metadata in some situations. An attacker could use
this to construct a malicious XFS image that, when mounted, could cause a
denial of service (system crash). (CVE-2018-10322)

Jay Shin discovered that the ext4 file system implementation in the Linux
kernel did not properly handle directory access with broken indexing,
leading to an out-of-bounds read vulnerability. A local attacker could use
this to cause a denial of service (system crash). (CVE-2020-14314)

It was discovered that a race condition existed in the hugetlb sysctl
implementation in the Linux kernel. A privileged attacker could use this to
cause a denial of service (system crash). (CVE-2020-25285)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
linux-image-4.4.0-1082-kvm 4.4.0-1082.91
linux-image-4.4.0-1117-aws 4.4.0-1117.131
linux-image-4.4.0-1141-raspi2 4.4.0-1141.151
linux-image-4.4.0-1145-snapdragon 4.4.0-1145.155
linux-image-4.4.0-193-generic 4.4.0-193.224
linux-image-4.4.0-193-generic-lpae 4.4.0-193.224
linux-image-4.4.0-193-lowlatency 4.4.0-193.224
linux-image-4.4.0-193-powerpc-e500mc 4.4.0-193.224
linux-image-4.4.0-193-powerpc-smp 4.4.0-193.224
linux-image-4.4.0-193-powerpc64-emb 4.4.0-193.224
linux-image-4.4.0-193-powerpc64-smp 4.4.0-193.224
linux-image-aws 4.4.0.1117.122
linux-image-generic 4.4.0.193.199
linux-image-generic-lpae 4.4.0.193.199
linux-image-kvm 4.4.0.1082.80
linux-image-lowlatency 4.4.0.193.199
linux-image-powerpc-e500mc 4.4.0.193.199
linux-image-powerpc-smp 4.4.0.193.199
linux-image-powerpc64-emb 4.4.0.193.199
linux-image-powerpc64-smp 4.4.0.193.199
linux-image-raspi2 4.4.0.1141.141
linux-image-snapdragon 4.4.0.1145.137
linux-image-virtual 4.4.0.193.199

Ubuntu 14.04 ESM:
linux-image-4.4.0-1081-aws 4.4.0-1081.85
linux-image-4.4.0-193-generic 4.4.0-193.224~14.04.1
linux-image-4.4.0-193-generic-lpae 4.4.0-193.224~14.04.1
linux-image-4.4.0-193-lowlatency 4.4.0-193.224~14.04.1
linux-image-aws 4.4.0.1081.78
linux-image-generic-lpae-lts-xenial 4.4.0.193.169
linux-image-generic-lts-xenial 4.4.0.193.169
linux-image-lowlatency-lts-xenial 4.4.0.193.169
linux-image-virtual-lts-xenial 4.4.0.193.169

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/4579-1
CVE-2018-10322, CVE-2020-14314, CVE-2020-16119, CVE-2020-25285

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.4.0-193.224
https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1117.131
https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1082.91
https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1141.151
https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1145.155

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAl+GYzkACgkQLwmejQBe
gfRWKg/8DUsk1RSycuiYvetTQ5WFXuxj9ZYHNjNM8n+6tdMzOkgERoejDBfVyTd5
Ui4HFrZSnQeIFFteF0qTHvLdONKdfcEu3UgB3RgwvGOsIENJTwKvMAJlEvRsL+fb
hDXBprQy9wX3lmqECftYTsTsWfEIHN6ofzl8is1bB/nLWbRaMBoZhFLOp3GpOLzE
HrHg5AarOiRL4l8ggWbBD9AL8yMK6trNa/zdzt5h3YvC9nZmj7VospM+CFuvDbSv
LhrfVEMAxMPPFm68wjHLDl9Z8qH6ti9fG0QdIGsxqPyU8HD9sX8muwh65ymiiHM2
IIVNZREH7MYZoEIZJlaEkP0SjsHPZFQ22A5P4X6u8wYnK2r9A+peB0obhwCOAdmN
bGDewDd886U3DyNQOl2u/QJ/I3zzUw8VJGlgDFKPxwdKQW8oLV5kM4z8pNvGEBdt
iws0LVtV84ct4EhoSmoGfarN2zdQZcmLCRE3th+SwyYnnkUPHUH6ir+3ONeOE/Sr
k8nEWYP5/Iafu2e++DEm8C40BhCSBTNybZUFWtjPuNjU2BiQARqeI0XjclEtN2LP
BGe3LFgV9gdprj1VB7Og0P/hGXvfzwAcjFiBOWeDrUst6/kI1X9nUIrXLUBBooai
3u2bJOVlLR7uSh9bRjkV1O6zBUKCrb3HHKhyfOymzB96bVMHVPo=
=XcB1
—–END PGP SIGNATURE—–

AutorBruno Varga
Cert idNCERT-REF-2020-10-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa dom4j

Otkriven je sigurnosni nedostatak u programskom paketu dom4j za operacijski sustav Ubuntu. Otkriveni nedostatak potencijalnim napadačima omogućuje izvršavanje proizvoljnog programskog...

Close