You are here
Home > Preporuke > Sigurnosni nedostaci jezgre operacijskog sustava

Sigurnosni nedostaci jezgre operacijskog sustava

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3678-1
June 12, 2018

linux, linux-aws, linux-gcp, linux-kvm vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux: Linux kernel
– linux-aws: Linux kernel for Amazon Web Services (AWS) systems
– linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
– linux-kvm: Linux kernel for cloud environments

Details:

Wen Xu discovered that the ext4 filesystem implementation in the Linux
kernel did not properly handle corrupted meta data in some situations. An
attacker could use this to specially craft an ext4 file system that caused
a denial of service (system crash) when mounted. (CVE-2018-1092)

It was discovered that the 802.11 software simulator implementation in the
Linux kernel contained a memory leak when handling certain error
conditions. A local attacker could possibly use this to cause a denial of
service (memory exhaustion). (CVE-2018-8087)

It was discovered that a memory leak existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (memory exhaustion).
(CVE-2018-10021)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
linux-image-4.15.0-1009-gcp 4.15.0-1009.9
linux-image-4.15.0-1010-aws 4.15.0-1010.10
linux-image-4.15.0-1011-kvm 4.15.0-1011.11
linux-image-4.15.0-23-generic 4.15.0-23.25
linux-image-4.15.0-23-generic-lpae 4.15.0-23.25
linux-image-4.15.0-23-lowlatency 4.15.0-23.25
linux-image-4.15.0-23-snapdragon 4.15.0-23.25
linux-image-aws 4.15.0.1010.10
linux-image-gcp 4.15.0.1009.11
linux-image-generic 4.15.0.23.25
linux-image-generic-lpae 4.15.0.23.25
linux-image-gke 4.15.0.1009.11
linux-image-kvm 4.15.0.1011.11
linux-image-lowlatency 4.15.0.23.25
linux-image-snapdragon 4.15.0.23.25

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/usn/usn-3678-1
CVE-2018-10021, CVE-2018-1092, CVE-2018-8087

Package Information:
https://launchpad.net/ubuntu/+source/linux/4.15.0-23.25
https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1010.10
https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1009.9
https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1011.11

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAlsfLcEACgkQLwmejQBe
gfTxBg//akUeo44RbErhtkovW3jQwa3ZNFmSA9bfqi+PeSHW6H8shClG4QBIs4W3
HMz/pqnY37dubf94GSHhRPoE8Gb7p3sruWFgGpQEJthCsOm4C6eBYo3yZO5v/gfL
eZ7IHM+7p/Exq5sXF3KlhiPn/ZD9GbrQYcJS2adRZHPlZcloQtXfkcGikDQ5ZikY
C/UTqbhIay3D8D1iESFTPgXD3PXYfkcIsGht5tqVl2sqQVDXKLQdcUwxbw6MraVL
iPLAe/wDHiirdKpkWm2sOvC8N2ZUlIplfmCUqfFSS6lJJ6tHxsOgQPj2xWachb7J
6qNYucJSbv0BZdq1hdsvJww4OUpb7V7ByeVB6O/xIpe7DTxB/ZnAUvR3ny/CdZ58
xholpEoY1Qn7dRxy3XzSL7pIA/kBc+aiIOPY8cT908uOiTp8PZVVFplch4sHIl+6
5pqhK2CTCX7a5SjxEKOi6r8RbuIVwFZJVKUVACrGmu39V4v32ZWKt8z2Qy6V73Fa
Fs5cvaDyTnBb1sN7BX2uovw8QEAOVo8bcZj4bOCA2+j8wcHcR5Kek2w0688wSeA1
jGC7NShYjTpw6iaCs5VO+D4b2+fx5ydRe9ixQRTq7KrbGlpw5ZDZRj0iNtc3JX8I
TBJkEYX065zC7zzWzXaf2Tosy/sXmFvHHASgJse3UQKmRBPljwg=
=3qrV
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-3678-2
June 12, 2018

linux-azure vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
– linux-azure: Linux kernel for Microsoft Azure Cloud systems

Details:

Wen Xu discovered that the ext4 filesystem implementation in the Linux
kernel did not properly handle corrupted meta data in some situations. An
attacker could use this to specially craft an ext4 file system that caused
a denial of service (system crash) when mounted. (CVE-2018-1092)

It was discovered that the 802.11 software simulator implementation in the
Linux kernel contained a memory leak when handling certain error
conditions. A local attacker could possibly use this to cause a denial of
service (memory exhaustion). (CVE-2018-8087)

It was discovered that a memory leak existed in the Serial Attached SCSI
(SAS) implementation in the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (memory exhaustion).
(CVE-2018-10021)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
linux-image-4.15.0-1013-azure 4.15.0-1013.13~16.04.2
linux-image-azure 4.15.0.1013.20

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://usn.ubuntu.com/usn/usn-3678-2
https://usn.ubuntu.com/usn/usn-3678-1
CVE-2018-10021, CVE-2018-1092, CVE-2018-8087

Package Information:
https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1013.13~16.04.2

—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAlsfLfQACgkQLwmejQBe
gfSVmhAAsLpd6AZi59qCF6I1WF3gxk2VKhSAb+UEeCEam6l7hclTq1WyQl8Rkh9R
pbLyjOlW7EJGKHRhBb3gFqhxO3GIB6wmNVt+0E2qon5HrUEH90hhuizlp74tysVd
h87wnYBxfWGxHb0sa9HnDZYZd0cQP4vTdtia99NBIgi0OOuEj9VL/NLcK18RBEW6
XqDR5L4iJUoL4Clp7pVeECd/qr753mAbjMubzEtUoVJ0Mxz0SRqUSBUy/Mu2Z2tE
yhpCIFKlRtPfQ8nKtEQEbppTFaxqxjyCc2uHBkYP4UjA84cZJ9/U/3TzWV9KBkdg
PozJ+Dl1BqIDgGOavdiTXq3MlWYXxqwpc7tyQMMbckTZo+mnepebPedcXvYNcI1x
QAMjwE6T6Y0oxDb/UBdqlLZrOl6lrV6W2mChf2oxuGUVqB/SSKMMG6GGq00BoJgy
8C+132YERJek2UpjdXeuMxhPwAAdI7AWQ7H4yCX0ZfewylUtDYgSHuBfa2sbEAkm
nGnwN7rLVCLVr6aymBnYTiL9NuHsHz6X2kTCPca9mOPvn+WhzdMOXVj6xTYIRjfu
6zhHBQruGNALyPzg0CptEREReq/B7LQGbqw/ZG6uaKz2mXRgxRXM/ThzBYpmClGt
HIAyugguWvNYA6E2ietJQ3+O9IG8Qt+Dp+NbXH8wVcsIbWaRbok=
=+CbK
—–END PGP SIGNATURE—–

AutorVlatka Misic
Cert idNCERT-REF-2018-06-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci jezgre operacijskog sustava

Otkrivene su ranjivosti u više verzija jezgre operacijskog sustava Ubuntu. Ranjivosti zahvaćaju određene komponente, a ovisno o tipu ranjivosti mogu...

Close