Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Ubuntu 17.10: USN-3505-1 Critical Wireless Firmware Threats

Ubuntu Large Esm H500
Several security issues were fixed in linux-firmware.
=========================================================================Ubuntu Security Notice USN-3505-1
December 06, 2017

linux-firmware vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 17.10
- Ubuntu 17.04
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in linux-firmware.

Software Description:
- linux-firmware: Firmware for Linux kernel drivers
Details:

Mathy Vanhoef discovered that the firmware for several Intel WLAN
devices incorrectly handled WPA2 in relation to Wake on WLAN. A
remote attacker could use this issue with key reinstallation attacks
to obtain sensitive information. (CVE-2017-13080, CVE-2017-13081)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.10:
  linux-firmware                  1.169.1

Ubuntu 17.04:
  linux-firmware                  1.164.2

Ubuntu 16.04 LTS:
  linux-firmware                  1.157.14

Ubuntu 14.04 LTS:
  linux-firmware                  1.127.24

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3505-1
  CVE-2017-13080, CVE-2017-13081

Package Information:
  https://launchpad.net/ubuntu/+source/linux-firmware/1.169.1
  https://launchpad.net/ubuntu/+source/linux-firmware/1.164.2
  https://launchpad.net/ubuntu/+source/linux-firmware/1.157.14
  https://launchpad.net/ubuntu/+source/linux-firmware/1.127.24

Ubuntu 17.10: USN-3505-1 Critical Wireless Firmware Threats

ubuntu
Calendar Grey December 6, 2017
Dist Ubuntu Esm H88
Significant flaws discovered in Linux firmware impacting Ubuntu distributions have been resolved. Upgrade promptly to enhance your system's protection.
Several security issues were fixed in linux-firmware.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10: linux-firmware 1.169.1 Ubuntu 17.04: linux-firmware 1.164.2 Ubuntu 16.04 LTS: linux-firmware 1.157.14 Ubuntu 14.04 LTS: linux-firmware 1.127.24 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3505-1

CVE-2017-13080, CVE-2017-13081

Severity
critical
Lowest
Low
Medium
High
Critical

December 06, 2017

Package Information

https://launchpad.net/ubuntu/+source/linux-firmware/1.169.1 https://launchpad.net/ubuntu/+source/linux-firmware/1.164.2 https://launchpad.net/ubuntu/+source/linux-firmware/1.157.14 https://launchpad.net/ubuntu/+source/linux-firmware/1.127.24

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here