Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5500-1 July 01, 2022 linux, linux-aws vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems Details: Eric Biederman discovered that the cgroup process migration implementation in the Linux kernel did not perform permission checks correctly in some situations. A local attacker could possibly use this to gain administrative privileges. (CVE-2021-4197) Lin Ma discovered that the NFC Controller Interface (NCI) implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-4202) It was discovered that the PF_KEYv2 implementation in the Linux kernel did not properly initialize kernel memory in some situations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2022-1353) It was discovered that the virtual graphics memory manager implementation in the Linux kernel was subject to a race condition, potentially leading to an information leak. (CVE-2022-1419) Minh Yuan discovered that the floppy disk driver in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1652) It was discovered that the Atheros ath9k wireless device driver in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could usethis to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1679) It was discovered that the Marvell NFC device driver implementation in the Linux kernel did not properly perform memory cleanup operations in some situations, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system) or execute arbitrary code. (CVE-2022-1734) 赵子轩 discovered that the 802.2 LLC type 2 driver in the Linux kernel did not properly perform reference counting in some error conditions. A local attacker could use this to cause a denial of service. (CVE-2022-28356) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: linux-image-4.4.0-1145-aws 4.4.0-1145.160 linux-image-4.4.0-229-generic 4.4.0-229.263 linux-image-4.4.0-229-lowlatency 4.4.0-229.263 linux-image-aws 4.4.0.1145.149 linux-image-generic 4.4.0.229.235 linux-image-lowlatency 4.4.0.229.235 linux-image-virtual 4.4.0.229.235 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5500-1 CVE-2021-4197, CVE-2021-4202, CVE-2022-1353, CVE-2022-1419, CVE-2022-1652, CVE-2022-1679, CVE-2022-1734, CVE-2022-28356 . Numerous security patches for the Linux kernel on Ubuntu 16.04 ESM have been addressed, tackling issues related to denial of service and potential information disclosures..Linux Kernel, Ubuntu Update, Security Patches, Denial of Service, Information Security. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the kernel.. Linux kernel vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary Several security issues were fixed in the kernel. Software Description - linux - Linux kernel - linux-aws - Linux kernel for Amazon Web Services (AWS) systems - linux-azure - Linux kernel for Microsoft Azure Cloud systems - linux-gcp - Linux kernel for Google Cloud Platform (GCP) systems - linux-gke - Linux kernel for Google Container Engine (GKE) systems - linux-gkeop - Linux kernel for Google Container Engine (GKE) systems - linux-ibm - Linux kernel for IBM cloud systems - linux-oem - Linux kernel for OEM systems Details Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) Nick Gregory discovered that the Linux kernel incorrectly handled network offload functionality. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2022-25636) Update instructions The problem can be corrected by updating your kernel livepatch to the following versions: Ubuntu 20.04 LTS aws - 85.1 azure - 85.1 gcp - 85.1 generic - 85.1 gke - 85.1 gkeop - 85.1 ibm - 85.1 lowlatency - 85.1 Ubuntu 18.04 LTS aws - 85.1 azure - 85.1 generic - 85.1 generic - 85.2 gke - 85.1 gkeop - 85.1 ibm - 85.1 lowlatency - 85.1 lowlatency - 85.2 oem - 85.1 Ubuntu 16.04 ESM aws - 85.1 azure - 85.1 generic - 85.1 lowlatency - 85.1 Ubuntu 14.04 ESM generic - 85.1 lowlatency - 85.1 Support Information Kernels older than the levels listed below do not receive livepatch updates. If you are running a kernel version earlier than the one listed below, please upgradeyour kernel as soon as possible. Ubuntu 20.04 LTS linux-aws - 5.4.0-1009 linux-azure - 5.4.0-1010 linux-gcp - 5.4.0-1009 linux-gke - 5.4.0-1033 linux-gkeop - 5.4.0-1009 linux-ibm - 5.4.0-1009 linux-oem - 5.4.0-26 linux - 5.4.0-26 Ubuntu 18.04 LTS linux-aws - 4.15.0-1054 linux-azure-4.15 - 4.15.0-1115 linux-azure-5.4 - 5.4.0-1069 linux-gke-4.15 - 4.15.0-1076 linux-gke-5.4 - 5.4.0-1009 linux-gkeop-5.4 - 5.4.0-1007 linux-hwe-5.4 - 5.4.0-26 linux-ibm-5.4 - 5.4.0-1009 linux-oem - 4.15.0-1063 linux - 4.15.0-69 Ubuntu 16.04 ESM linux-aws - 4.4.0-1098 linux-azure - 4.15.0-1063 linux-hwe - 4.15.0-69 linux - 4.4.0-168 Ubuntu 14.04 ESM linux-lts-xenial - 4.4.0-168 References - CVE-2022-0492 - CVE-2022-25636 . Various vulnerabilities within the Ubuntu Linux kernel might enable malicious actors to escalate their privileges or trigger service disruptions.. Kernel Security Issues, Ubuntu Patch Management, Local Attack Prevention. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5302-1 February 22, 2022 linux-oem-5.14 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-oem-5.14: Linux kernel for OEM systems Details: Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) Brendan Dolan-Gavitt discovered that the Marvell WiFi-Ex USB device driver in the Linux kernel did not properly handle some error conditions. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2021-43976) Wenqing Liu discovered that the f2fs file system implementation in the Linux kernel did not properly validate inode types while performing garbage collection. An attacker could use this to construct a malicious f2fs image that, when mounted and operated on, could cause a denial of service (system crash). (CVE-2021-44879) Samuel Page discovered that the Transparent Inter-Process Communication (TIPC) protocol implementation in the Linux kernel contained a stack-based buffer overflow. A remote attacker could use this to cause a denial of service (system crash) for systems that have a TIPC bearer configured. (CVE-2022-0435) Lyu Tao discovered that the NFS implementation in the Linux kernel did not properly handle requests to open a directory on a regular file. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2022-24448) It was discovered that the YAM AX.25 device driver in the Linux kernel did not properly deallocate memory in some error conditions. A local privilegedattacker could use this to cause a denial of service (kernel memory exhaustion). (CVE-2022-24959) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.14.0-1024-oem 5.14.0-1024.26 linux-image-oem-20.04 5.14.0.1024.22 linux-image-oem-20.04b 5.14.0.1024.22 linux-image-oem-20.04c 5.14.0.1024.22 linux-image-oem-20.04d 5.14.0.1024.22 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5302-1 CVE-2021-43976, CVE-2021-44879, CVE-2022-0435, CVE-2022-0492, CVE-2022-24448, CVE-2022-24959 Package Information: https://launchpad.net/ubuntu/+source/linux-oem-5.14/5.14.0-1024.26 . Tackling security vulnerabilities in Ubuntu 20.04 LTS that impact the Linux kernel through essential updates for kernel environments.. Linux Kernel Issues, Ubuntu Security Notice, Kernel Updates, Administrative Privileges. . LinuxSecurity.com Team
The system could be made to crash or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-4484-1 September 02, 2020 linux-hwe, linux-aws-5.3, linux-gke-5.3, linux-raspi2-5.3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: - linux-aws-5.3: Linux kernel for Amazon Web Services (AWS) systems - linux-gke-5.3: Linux kernel for Google Container Engine (GKE) systems - linux-hwe: Linux hardware enablement (HWE) kernel - linux-raspi2-5.3: Linux kernel for Raspberry Pi (V8) systems Details: It was discovered that the cgroup v2 subsystem in the Linux kernel did not properly perform reference counting in some situations, leading to a NULL pointer dereference. A local attacker could use this to cause a denial of service or possibly gain administrative privileges. (CVE-2020-14356) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-5.3.0-1032-raspi2 5.3.0-1032.34 linux-image-5.3.0-1034-aws 5.3.0-1034.36 linux-image-5.3.0-1034-gke 5.3.0-1034.36 linux-image-5.3.0-66-generic 5.3.0-66.60 linux-image-5.3.0-66-lowlatency 5.3.0-66.60 linux-image-aws 5.3.0.1034.33 linux-image-gke-5.3 5.3.0.1034.19 linux-image-gkeop-5.3 5.3.0.66.123 linux-image-raspi2-hwe-18.04 5.3.0.1032.22 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g.linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4484-1 CVE-2020-14356 Package Information: https://launchpad.net/ubuntu/+source/linux-aws-5.3/5.3.0-1034.36 https://launchpad.net/ubuntu/+source/linux-gke-5.3/5.3.0-1034.36 https://launchpad.net/ubuntu/+source/linux-hwe/5.3.0-66.60 https://launchpad.net/ubuntu/+source/linux-raspi2-5.3/5.3.0-1032.34 . Significant vulnerability identified in Ubuntu's Linux kernel; addresses risks for service interruption and unauthorized privilege elevation.. Linux Kernel, Ubuntu Security, Denial of Service, Privilege Escalation. . Severity: Critical. LinuxSecurity.com Team
This update is based on upstream 5.5.14 and fixes atleast the following security vulnerabilities: In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h) . MGASA-2020-0156 - Updated kernel packages fix security vulnerabilities Publication date: 02 Apr 2020 URL: https://advisories.mageia.org/MGASA-2020-0156.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-19769, CVE-2020-8835 This update is based on upstream 5.5.14 and fixes atleast the following security vulnerabilities: In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h) (CVE-2019-19769). Manfred Paul discovered that the bpf verifier in the Linux kernel did not properly calculate register bounds for certain operations. A local attacker could use this to expose sensitive information (kernel memory) or gain administrative privileges (CVE-2020-8835). Security fixes and hardenings to the mac00211 layer to prevent leaking keys and frames. Other notable changes in this update: - WireGuard kernel module has been updated to v1.0.20200330 and the tools to v1.0.20200319. - exfat-utils has been rebuilt in core (was previously in tainted) as we now also ship the official upstream exfat driver. For other upstream fixes in this update, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=26420 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.10 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.11 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.12 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.13 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.14 - https://www.cve.org/CVERecord?id=CVE-2019-19769 - https://www.cve.org/CVERecord?id=CVE-2020-8835 SRPMS: - 7/core/kernel-5.5.14-1.mga7 - 7/core/kmod-virtualbox-6.0.18-8.mga7 - 7/core/kmod-xtables-addons-3.8-8.mga7 -7/core/wireguard-tools-1.0.20200319-1.mga7 - 7/core/exfat-utils-1.3.0-2.mga7 . Mageia 2021-0167 enhances kernel components to address security issues, such as buffer overflow and privilege escalation.. kernel Security Update, Mageia 2020-0156, security fixes, Linux kernel issues, administrative privileges. . LinuxSecurity.com Team
The system could be made to expose sensitive information or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-4313-1 March 30, 2020 linux, linux-aws, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-oracle-5.3, linux-raspi2, linux-raspi2-5.3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 18.04 LTS Summary: The system could be made to expose sensitive information or run programs as an administrator. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi2: Linux kernel for Raspberry Pi 2 - linux-azure-5.3: Linux kernel for Microsoft Azure Cloud systems - linux-gcp-5.3: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke-5.3: Linux kernel for Google Container Engine (GKE) systems - linux-hwe: Linux hardware enablement (HWE) kernel - linux-oracle-5.3: Linux kernel buildinfo for version 5.3.0 on 64 bit x86 SMP - linux-raspi2-5.3: Linux kernel for Raspberry Pi 2 Details: Manfred Paul discovered that the bpf verifier in the Linux kernel did not properly calculate register bounds for certain operations. A local attacker could use this to expose sensitive information (kernel memory) or gain administrative privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: linux-image-5.3.0-1013-oracle 5.3.0-1013.14 linux-image-5.3.0-1014-kvm 5.3.0-1014.15 linux-image-5.3.0-1015-aws 5.3.0-1015.16 linux-image-5.3.0-1016-gcp 5.3.0-1016.17 linux-image-5.3.0-1018-azure 5.3.0-1018.19 linux-image-5.3.0-1021-raspi2 5.3.0-1021.23 linux-image-5.3.0-45-generic 5.3.0-45.37 linux-image-5.3.0-45-generic-lpae 5.3.0-45.37 linux-image-5.3.0-45-lowlatency 5.3.0-45.37 linux-image-5.3.0-45-snapdragon 5.3.0-45.37 linux-image-aws 5.3.0.1015.17 linux-image-azure 5.3.0.1018.37 linux-image-gcp 5.3.0.1016.17 linux-image-generic 5.3.0.45.38 linux-image-generic-lpae 5.3.0.45.38 linux-image-gke 5.3.0.1016.17 linux-image-kvm 5.3.0.1014.16 linux-image-lowlatency 5.3.0.45.38 linux-image-oracle 5.3.0.1013.14 linux-image-raspi2 5.3.0.1021.18 linux-image-snapdragon 5.3.0.45.38 linux-image-virtual 5.3.0.45.38 Ubuntu 18.04 LTS: linux-image-5.3.0-1013-oracle 5.3.0-1013.14~18.04.1 linux-image-5.3.0-1016-gcp 5.3.0-1016.17~18.04.1 linux-image-5.3.0-1016-gke 5.3.0-1016.17~18.04.1 linux-image-5.3.0-1018-azure 5.3.0-1018.19~18.04.1 linux-image-5.3.0-1021-raspi2 5.3.0-1021.23~18.04.1 linux-image-5.3.0-45-generic 5.3.0-45.37~18.04.1 linux-image-5.3.0-45-generic-lpae 5.3.0-45.37~18.04.1 linux-image-5.3.0-45-lowlatency 5.3.0-45.37~18.04.1 linux-image-azure-edge 5.3.0.1018.18 linux-image-gcp-edge 5.3.0.1016.15 linux-image-generic-hwe-18.04 5.3.0.45.101 linux-image-generic-lpae-hwe-18.04 5.3.0.45.101 linux-image-gke-5.3 5.3.0.1016.6 linux-image-lowlatency-hwe-18.04 5.3.0.45.101 linux-image-oracle-edge 5.3.0.1013.12 linux-image-raspi2-hwe-18.04 5.3.0.1021.10 linux-image-snapdragon-hwe-18.04 5.3.0.45.101 linux-image-virtual-hwe-18.04 5.3.0.45.101 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompileand reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4313-1 CVE-2020-8835 Package Information: https://launchpad.net/ubuntu/+source/linux/5.3.0-45.37 https://launchpad.net/ubuntu/+source/linux-aws/5.3.0-1015.16 https://launchpad.net/ubuntu/+source/linux-azure/5.3.0-1018.19 https://launchpad.net/ubuntu/+source/linux-gcp/5.3.0-1016.17 https://launchpad.net/ubuntu/+source/linux-kvm/5.3.0-1014.15 https://launchpad.net/ubuntu/+source/linux-oracle/5.3.0-1013.14 https://launchpad.net/ubuntu/+source/linux-raspi2/5.3.0-1021.23 https://launchpad.net/ubuntu/+source/linux-azure-5.3/5.3.0-1018.19~18.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-5.3/5.3.0-1016.17~18.04.1 https://launchpad.net/ubuntu/+source/linux-gke-5.3/5.3.0-1016.17~18.04.1 https://launchpad.net/ubuntu/+source/linux-hwe/5.3.0-45.37~18.04.1 https://launchpad.net/ubuntu/+source/linux-oracle-5.3/5.3.0-1013.14~18.04.1 https://launchpad.net/ubuntu/+source/linux-raspi2-5.3/5.3.0-1021.23~18.04.1 . A vulnerability in the Linux kernel on Ubuntu may lead to unauthorized access or data leaks; patches have been released.. Ubuntu Kernel Issue, Security Update, Linux Vulnerability, System Admin Rights. . LinuxSecurity.com Team
gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password (CVE-2019-3827) SL7 x86_64 gvfs-1.36.2-3.el7.i686.rpm gvfs-smb-1.36.2-3.el7.x86_64.rpm gvfs-afp-1.36.2-3.el7.x86_64.rpm gvfs-mtp-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.x86_64.rpm gvfs-client-1.36.2-3.el7.x86_64.rpm gvfs [More...]. Synopsis: Moderate: gvfs security and bug fix update Advisory ID: SLSA-2019:2145-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2019-3827 -- Security Fix(es): * gvfs: Incorrect authorization in admin backend allows privileged usersto read and modify arbitrary files without prompting for password (CVE-2019-3827) -- SL7 x86_64 gvfs-1.36.2-3.el7.i686.rpm gvfs-smb-1.36.2-3.el7.x86_64.rpm gvfs-afp-1.36.2-3.el7.x86_64.rpm gvfs-mtp-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.x86_64.rpm gvfs-client-1.36.2-3.el7.x86_64.rpm gvfs-gphoto2-1.36.2-3.el7.x86_64.rpm gvfs-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.i686.rpm gvfs-client-1.36.2-3.el7.i686.rpm gvfs-afc-1.36.2-3.el7.x86_64.rpm gvfs-goa-1.36.2-3.el7.x86_64.rpm gvfs-fuse-1.36.2-3.el7.x86_64.rpm gvfs-archive-1.36.2-3.el7.x86_64.rpm gvfs-tests-1.36.2-3.el7.x86_64.rpm gvfs-debuginfo-1.36.2-3.el7.i686.rpm gvfs-debuginfo-1.36.2-3.el7.x86_64.rpm - Scientific Linux Development Team . Key gvfs security patch release for SL7.x correcting access control vulnerabilities permitting unauthorized file interactions.. gvfs, security fix, authorization issues, SL7, privileged access. . Severity: Important. LinuxSecurity.com Team
PolicyKit could allow unintended access.. =========================================================================Ubuntu Security Notice USN-3861-2 January 16, 2019 policykit-1 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: PolicyKit could allow unintended access. Software Description: - policykit-1: framework for managing administrative policies and privileges Details: USN-3861-1 fixed a vulnerability in PolicyKit. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that PolicyKit incorrectly handled certain large user UIDs. A local attacker with a large UID could possibly use this issue to perform privileged actions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: libpolkit-backend-1-0 0.104-1ubuntu1.4 policykit-1 0.104-1ubuntu1.4 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3861-1 CVE-2018-19788 . Ubuntu Security Notice USN-3862-1 addresses a vulnerability within the AppArmor service that enables unauthorized actions by local users.. PolicyKit Flaw, Ubuntu Security Update, Local Access Attack. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.