Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 DLA-3102-1: Critical Linux-5.10 Privilege Escalation

debian lts
Calendar Grey September 11, 2022
Dist Debian Esm H88
The Ubuntu security notice USN-1111-1 announces significant patches for the linux-hardened package, rectifying multiple vulnerabilities.
Linux 5.10 has been packaged for Debian 10 as linux-5.10

Summary

The "apt full-upgrade" command will *not* automatically install the
updated kernel packages. You should explicitly install one of the
following metapackages first, as appropriate for your system:

linux-image-5.10-686
linux-image-5.10-686-pae
linux-image-5.10-amd64
linux-image-5.10-arm64
linux-image-5.10-armmp
linux-image-5.10-armmp-lpae
linux-image-5.10-cloud-amd64
linux-image-5.10-cloud-arm64
linux-image-5.10-rt-686-pae
linux-image-5.10-rt-amd64
linux-image-5.10-rt-arm64
linux-image-5.10-rt-armmp

For example, if the command "uname -r" currently shows
"5.10.0-0.deb10.16-amd64", you should install linux-image-5.10-amd64.

This backport does not include the following binary packages:

bpftool hyperv-daemons libcpupower-dev libcpupower1
linux-compiler-gcc-8-arm linux-compiler-gcc-8-x86 linux-cpupower
linux-libc-dev usbip

Older versions of most of those are built from the linux source
package in Debian 10.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: linux-5.10
Version: 5.10.136-1~deb10u3
CVE ID: CVE-2022-2585 CVE-2022-2586 CVE-2022-2588 CVE-2022-26373

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here