Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Critical AppArmor Issue in Ubuntu 16.04 LTS: USN-3247-1 Advisory

Ubuntu Large Esm H500
AppArmor could remove the confinement from some programs.
=========================================================================Ubuntu Security Notice USN-3247-1
March 28, 2017

apparmor vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

AppArmor could remove the confinement from some programs.

Software Description:
- apparmor: Linux security system

Details:

Stéphane Graber discovered that AppArmor incorrectly unloaded some profiles
when restarted or upgraded, contrary to expected behavior.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  apparmor                        2.10.95-4ubuntu5.3

Ubuntu 16.04 LTS:
  apparmor                        2.10.95-0ubuntu2.6

Ubuntu 14.04 LTS:
  apparmor                        2.10.95-0ubuntu2.6~14.04.1

Ubuntu 12.04 LTS:
  apparmor                        2.7.102-0ubuntu3.11

After a standard system update you need to reboot your computer to make
all the necessary changes.

A new utility, called aa-remove-unknown, was added to assist with profiles that
would have been previously unloaded when AppArmor was restarted or upgraded.

References:
  https://ubuntu.com/security/notices/USN-3247-1
  CVE-2017-6507

Package Information:
  https://launchpad.net/ubuntu/+source/apparmor/2.10.95-4ubuntu5.3
  https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6
  https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1
  https://launchpad.net/ubuntu/+source/apparmor/2.7.102-0ubuntu3.11

Critical AppArmor Issue in Ubuntu 16.04 LTS: USN-3247-1 Advisory

ubuntu
Calendar Grey March 28, 2017
Dist Ubuntu Esm H88
A weakness in AppArmor may cause certain applications to lose their confinement. Discover the steps to resolve this issue in the latest advisory.
AppArmor could remove the confinement from some programs.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: apparmor 2.10.95-4ubuntu5.3 Ubuntu 16.04 LTS: apparmor 2.10.95-0ubuntu2.6 Ubuntu 14.04 LTS: apparmor 2.10.95-0ubuntu2.6~14.04.1 Ubuntu 12.04 LTS: apparmor 2.7.102-0ubuntu3.11 After a standard system update you need to reboot your computer to make all the necessary changes. A new utility, called aa-remove-unknown, was added to assist with profiles that would have been previously unloaded when AppArmor was restarted or upgraded.

References

https://ubuntu.com/security/notices/USN-3247-1

CVE-2017-6507

Severity
critical
Lowest
Low
Medium
High
Critical

March 28, 2017

Package Information

https://launchpad.net/ubuntu/+source/apparmor/2.10.95-4ubuntu5.3 https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6 https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1 https://launchpad.net/ubuntu/+source/apparmor/2.7.102-0ubuntu3.11

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here