Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu: 4008-3 Critical: Linux Kernel DoS and ASLR Issues

Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4008-3 June 07, 2019 linux-lts-xenial, linux-aws vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty Details: USN-4008-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 ESM. Robert Święcki discovered that the Linux kernel did not properly apply Address Space Layout Randomization (ASLR) in some situations for setuid elf binaries. A local attacker could use this to improve the chances of exploiting an existing vulnerability in a setuid elf binary. (CVE-2019-11190) It was discovered that a null pointer dereference vulnerability existed in the LSI Logic MegaRAID driver in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2019-11810) It was discovered that a race condition leading to a use-after-free existed in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel. The RDS protocol is blacklisted by default in Ubuntu. If enabled, a local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2019-11815) Federico Manuel Bento discovered that the Linux kernel did not properly apply Address Space Layout Randomization (ASLR) in some situations for setuid a.out binaries. A local attacker could use this to improve the chances of exploiting an existing vulnerability in a setuid a.outbinary. (CVE-2019-11191) As a hardening measure, this update disables a.out support. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: linux-image-4.4.0-1045-aws 4.4.0-1045.48 linux-image-4.4.0-150-generic 4.4.0-150.176~14.04.1 linux-image-4.4.0-150-generic-lpae 4.4.0-150.176~14.04.1 linux-image-4.4.0-150-lowlatency 4.4.0-150.176~14.04.1 linux-image-aws 4.4.0.1045.46 linux-image-generic-lpae-lts-xenial 4.4.0.150.132 linux-image-generic-lts-xenial 4.4.0.150.132 linux-image-lowlatency-lts-xenial 4.4.0.150.132 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4008-3 https://ubuntu.com/security/notices/USN-4008-1 CVE-2019-11190, CVE-2019-11191, CVE-2019-11810, CVE-2019-11815 . Critical patch release for Ubuntu kernel flaws on June 07, 2019, mitigating local exploitation threats through updates and corrective measures.. Linux Kernel, Security Update, Ubuntu Vulnerabilities, AWS Kernels, System Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 07, 2019 Critical Ubuntu
172

Ubuntu 18.04 LTS: USN-4007-1 Critical: Kernel ASLR Bypass

A system hardening measure could be bypassed.. =========================================================================Ubuntu Security Notice USN-4007-1 June 04, 2019 linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: A system hardening measure could be bypassed. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-meta: - linux-oem: Linux kernel for OEM processors - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi2: Linux kernel for Raspberry Pi 2 - linux-snapdragon: Linux kernel for Snapdragon processors Details: Federico Manuel Bento discovered that the Linux kernel did not properly apply Address Space Layout Randomization (ASLR) in some situations for setuid a.out binaries. A local attacker could use this to improve the chances of exploiting an existing vulnerability in a setuid a.out binary. As a hardening measure, this update disables a.out support. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-4.15.0-1014-oracle 4.15.0-1014.16 linux-image-4.15.0-1033-gcp 4.15.0-1033.35 linux-image-4.15.0-1035-kvm 4.15.0-1035.35 linux-image-4.15.0-1037-raspi2 4.15.0-1037.39 linux-image-4.15.0-1039-oem 4.15.0-1039.44 linux-image-4.15.0-1040-aws 4.15.0-1040.42 linux-image-4.15.0-1054-snapdragon 4.15.0-1054.58 linux-image-4.15.0-51-generic 4.15.0-51.55 linux-image-4.15.0-51-generic-lpae 4.15.0-51.55 linux-image-4.15.0-51-lowlatency 4.15.0-51.55 linux-image-aws 4.15.0.1040.39 linux-image-gcp 4.15.0.1033.35 linux-image-generic 4.15.0.51.53 linux-image-generic-lpae 4.15.0.51.53 linux-image-kvm 4.15.0.1035.35 linux-image-lowlatency 4.15.0.51.53 linux-image-oem 4.15.0.1039.43 linux-image-oracle 4.15.0.1014.17 linux-image-raspi2 4.15.0.1037.35 linux-image-snapdragon 4.15.0.1054.57 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4007-1 CVE-2019-11191 Package Information: https://launchpad.net/ubuntu/+source/linux/4.15.0-51.55 https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1040.42 https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1033.35 https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1035.35 https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.51.53 https://launchpad.net/ubuntu/+source/linux-oem/4.15.0-1039.44 https://launchpad.net/ubuntu/+source/linux-oracle/4.15.0-1014.16 https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1037.39 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1054.58 . Critical security notice for Ubuntu regarding a circumvention of kernel protection protocols impacting various deployments.. Ubuntu Security, Linux Kernel Issues, System Hardening, ASLR Bypass, Setuid Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 04, 2019 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here