Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8492-3 July 06, 2026 linux-raspi-realtime vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-raspi-realtime: Linux kernel for Raspberry Pi Real-time systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - ATM drivers; - RNBD block device driver; - Ublk userspace block driver; - Bus devices; - Character device driver; - TPM device driver; - Clock framework and drivers; - Clocksource drivers; - CPU idle management framework; - Hardware crypto device drivers; - DMA engine subsystem; - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - Multiple devices driver; - Media drivers; - Multifunction device drivers; - Broadcom VK accelerator driver; - MOST (Media Oriented Systems Transport) drivers; - MTD block device drivers; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - NTB driver; - NVME drivers; - PCI subsystem; - Performance monitor drivers; - Pin controllers subsystem; - x86 platform drivers; - Power supply drivers; - RapidIO drivers; - RAS (Reliability, Availability, Serviceability) subsystem; - Remote Processor subsystem; - RPMSG subsystem; - S/390 drivers; - SCSI subsystem; -MediaTek SoC drivers; - Texas Instruments SoC drivers; - SPI subsystem; - Greybus lights staging drivers; - Realtek RTL8723BS SDIO drivers; - UFS subsystem; - ChipIdea USB driver; - DesignWare USB3 driver; - USB over IP driver; - vDPA drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - BTRFS file system; - File systems infrastructure; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - FAT file system; - GFS2 file system; - HFS+ file system; - JFS file system; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - OCFS2 file system; - Proc file system; - Pstore file system; - Diskquota system; - SMB network file system; - XFS file system; - Audit subsystem; - Memory Management; - IPv6 networking; - Netfilter; - Tracing infrastructure; - Kernel kexec() syscall; - RCU subsystem; - Scheduler infrastructure; - Scatterlist API; - 9P file system network protocol; - Asynchronous Transfer Mode (ATM) subsystem; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - Ethernet bridge; - Ceph Core library; - Networking core; - IPv4 networking; - KCM (Kernel Connection Multiplexor) sockets driver; - Multipath TCP; - NFC subsystem; - RDS protocol; - RxRPC session sockets; - Network traffic control; - SMC sockets; - Sun RPC protocol; - X.25 network layer; - XFRM subsystem; - AppArmor security module; - Simplified Mandatory Access Control Kernel framework; - SOF drivers; - USB sound devices; (CVE-2025-40005, CVE-2025-71229, CVE-2025-71231, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235, CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71272, CVE-2025-71273, CVE-2025-71274, CVE-2025-71286, CVE-2025-71291, CVE-2025-71292, CVE-2025-71294, CVE-2025-71295, CVE-2025-71297, CVE-2025-71304, CVE-2025-71305, CVE-2026-23100, CVE-2026-23169, CVE-2026-23220,CVE-2026-23221, CVE-2026-23222, CVE-2026-23228, CVE-2026-23229, CVE-2026-23230, CVE-2026-23233, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236, CVE-2026-23237, CVE-2026-23238, CVE-2026-23241, CVE-2026-23242, CVE-2026-23243, CVE-2026-23249, CVE-2026-23266, CVE-2026-23267, CVE-2026-23272, CVE-2026-23278, CVE-2026-23392, CVE-2026-23428, CVE-2026-23450, CVE-2026-23455, CVE-2026-31402, CVE-2026-31411, CVE-2026-31418, CVE-2026-31436, CVE-2026-31448, CVE-2026-31478, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668, CVE-2026-31669, CVE-2026-31682, CVE-2026-31685, CVE-2026-31687, CVE-2026-31693, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43071, CVE-2026-43114, CVE-2026-43117, CVE-2026-43123, CVE-2026-43124, CVE-2026-43128, CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134, CVE-2026-43135, CVE-2026-43136, CVE-2026-43137, CVE-2026-43139, CVE-2026-43140, CVE-2026-43141, CVE-2026-43143, CVE-2026-43145, CVE-2026-43147, CVE-2026-43148, CVE-2026-43149, CVE-2026-43150, CVE-2026-43152, CVE-2026-43153, CVE-2026-43156, CVE-2026-43157, CVE-2026-43158, CVE-2026-43159, CVE-2026-43163, CVE-2026-43167, CVE-2026-43168, CVE-2026-43169, CVE-2026-43170, CVE-2026-43171, CVE-2026-43173, CVE-2026-43175, CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184, CVE-2026-43186, CVE-2026-43187, CVE-2026-43189, CVE-2026-43190, CVE-2026-43194, CVE-2026-43196, CVE-2026-43199, CVE-2026-43200, CVE-2026-43201, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205, CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211, CVE-2026-43212, CVE-2026-43214, CVE-2026-43215, CVE-2026-43218, CVE-2026-43221, CVE-2026-43222, CVE-2026-43223, CVE-2026-43225, CVE-2026-43226, CVE-2026-43227, CVE-2026-43230, CVE-2026-43231, CVE-2026-43232, CVE-2026-43233, CVE-2026-43236, CVE-2026-43238, CVE-2026-43239, CVE-2026-43241, CVE-2026-43242, CVE-2026-43244, CVE-2026-43246, CVE-2026-43248, CVE-2026-43249, CVE-2026-43250, CVE-2026-43251, CVE-2026-43253, CVE-2026-43255, CVE-2026-43256, CVE-2026-43257,CVE-2026-43258, CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43266, CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43271, CVE-2026-43273, CVE-2026-43275, CVE-2026-43277, CVE-2026-43278, CVE-2026-43279, CVE-2026-43283, CVE-2026-43287, CVE-2026-43288, CVE-2026-43289, CVE-2026-43291, CVE-2026-43295, CVE-2026-43296, CVE-2026-43297, CVE-2026-43300, CVE-2026-43302, CVE-2026-43304, CVE-2026-43312, CVE-2026-43313, CVE-2026-43314, CVE-2026-43315, CVE-2026-43316, CVE-2026-43317, CVE-2026-43318, CVE-2026-43319, CVE-2026-43320, CVE-2026-43341, CVE-2026-43378, CVE-2026-43383, CVE-2026-43384, CVE-2026-43406, CVE-2026-43407, CVE-2026-43414, CVE-2026-43493, CVE-2026-43501, CVE-2026-45847, CVE-2026-45848, CVE-2026-45849, CVE-2026-45851, CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45859, CVE-2026-45860, CVE-2026-45861, CVE-2026-45862, CVE-2026-45864, CVE-2026-45865, CVE-2026-45866, CVE-2026-45867, CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871, CVE-2026-45872, CVE-2026-45873, CVE-2026-45875, CVE-2026-45877, CVE-2026-45878, CVE-2026-45879, CVE-2026-45880, CVE-2026-45881, CVE-2026-45882, CVE-2026-45883, CVE-2026-45884, CVE-2026-45885, CVE-2026-45886, CVE-2026-45890, CVE-2026-45891, CVE-2026-45893, CVE-2026-45895, CVE-2026-45902, CVE-2026-45904, CVE-2026-45905, CVE-2026-45910, CVE-2026-45912, CVE-2026-45913, CVE-2026-45914, CVE-2026-45915, CVE-2026-45916, CVE-2026-45917, CVE-2026-45919, CVE-2026-45921, CVE-2026-45923, CVE-2026-45928, CVE-2026-45935, CVE-2026-45936, CVE-2026-45938, CVE-2026-45941, CVE-2026-45946, CVE-2026-45947, CVE-2026-45948, CVE-2026-45954, CVE-2026-45957, CVE-2026-45960, CVE-2026-45962, CVE-2026-45964, CVE-2026-45965, CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45972, CVE-2026-45973, CVE-2026-45974, CVE-2026-45976, CVE-2026-45978, CVE-2026-45981, CVE-2026-45982, CVE-2026-45983, CVE-2026-45984, CVE-2026-45988, CVE-2026-46043, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135, CVE-2026-46185, CVE-2026-46195, CVE-2026-46243, CVE-2026-46244, CVE-2026-46246,CVE-2026-46247, CVE-2026-46249, CVE-2026-46250, CVE-2026-46251, CVE-2026-46253, CVE-2026-46254, CVE-2026-46255, CVE-2026-46259, CVE-2026-46260, CVE-2026-46261, CVE-2026-46265, CVE-2026-46266, CVE-2026-46267, CVE-2026-46270, CVE-2026-46289, CVE-2026-46328) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-2049-raspi-realtime 6.8.0-2049.50 Available with Ubuntu Pro linux-image-raspi-realtime 6.8.0-2049.50 Available with Ubuntu Pro linux-image-raspi-realtime-6.8 6.8.0-2049.50 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8492-3 https://ubuntu.com/security/notices/USN-8492-2 https://ubuntu.com/security/notices/USN-8492-1 CVE-2025-40005, CVE-2025-71229, CVE-2025-71231, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235, CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239, CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71272, CVE-2025-71273, CVE-2025-71274, CVE-2025-71286, CVE-2025-71291, CVE-2025-71292, CVE-2025-71294, CVE-2025-71295, CVE-2025-71297, CVE-2025-71304, CVE-2025-71305, CVE-2026-23100, CVE-2026-23169, CVE-2026-23220, CVE-2026-23221, CVE-2026-23222, CVE-2026-23228, CVE-2026-23229, CVE-2026-23230, CVE-2026-23233, CVE-2026-23234, CVE-2026-23235, CVE-2026-23236, CVE-2026-23237, CVE-2026-23238, CVE-2026-23241,CVE-2026-23242, CVE-2026-23243, CVE-2026-23249, CVE-2026-23266, CVE-2026-23267, CVE-2026-23272, CVE-2026-23278, CVE-2026-23392, CVE-2026-23428, CVE-2026-23450, CVE-2026-23455, CVE-2026-31402, CVE-2026-31411, CVE-2026-31418, CVE-2026-31436, CVE-2026-31448, CVE-2026-31478, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668, CVE-2026-31669, CVE-2026-31682, CVE-2026-31685, CVE-2026-31687, CVE-2026-31693, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43071, CVE-2026-43114, CVE-2026-43117, CVE-2026-43123, CVE-2026-43124, CVE-2026-43128, CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134, CVE-2026-43135, CVE-2026-43136, CVE-2026-43137, CVE-2026-43139, CVE-2026-43140, CVE-2026-43141, CVE-2026-43143, CVE-2026-43145, CVE-2026-43147, CVE-2026-43148, CVE-2026-43149, CVE-2026-43150, CVE-2026-43152, CVE-2026-43153, CVE-2026-43156, CVE-2026-43157, CVE-2026-43158, CVE-2026-43159, CVE-2026-43163, CVE-2026-43167, CVE-2026-43168, CVE-2026-43169, CVE-2026-43170, CVE-2026-43171, CVE-2026-43173, CVE-2026-43175, CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184, CVE-2026-43186, CVE-2026-43187, CVE-2026-43189, CVE-2026-43190, CVE-2026-43194, CVE-2026-43196, CVE-2026-43199, CVE-2026-43200, CVE-2026-43201, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205, CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211, CVE-2026-43212, CVE-2026-43214, CVE-2026-43215, CVE-2026-43218, CVE-2026-43221, CVE-2026-43222, CVE-2026-43223, CVE-2026-43225, CVE-2026-43226, CVE-2026-43227, CVE-2026-43230, CVE-2026-43231, CVE-2026-43232, CVE-2026-43233, CVE-2026-43236, CVE-2026-43238, CVE-2026-43239, CVE-2026-43241, CVE-2026-43242, CVE-2026-43244, CVE-2026-43246, CVE-2026-43248, CVE-2026-43249, CVE-2026-43250, CVE-2026-43251, CVE-2026-43253, CVE-2026-43255, CVE-2026-43256, CVE-2026-43257, CVE-2026-43258, CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43266, CVE-2026-43268, CVE-2026-43269, CVE-2026-43270,CVE-2026-43271, CVE-2026-43273, CVE-2026-43275, CVE-2026-43277, CVE-2026-43278, CVE-2026-43279, CVE-2026-43283, CVE-2026-43287, CVE-2026-43288, CVE-2026-43289, CVE-2026-43291, CVE-2026-43295, CVE-2026-43296, CVE-2026-43297, CVE-2026-43300, CVE-2026-43302, CVE-2026-43304, CVE-2026-43312, CVE-2026-43313, CVE-2026-43314, CVE-2026-43315, CVE-2026-43316, CVE-2026-43317, CVE-2026-43318, CVE-2026-43319, CVE-2026-43320, CVE-2026-43341, CVE-2026-43378, CVE-2026-43383, CVE-2026-43384, CVE-2026-43406, CVE-2026-43407, CVE-2026-43414, CVE-2026-43493, CVE-2026-43501, CVE-2026-45847, CVE-2026-45848, CVE-2026-45849, CVE-2026-45851, CVE-2026-45852, CVE-2026-45856, CVE-2026-45857, CVE-2026-45859, CVE-2026-45860, CVE-2026-45861, CVE-2026-45862, CVE-2026-45864, CVE-2026-45865, CVE-2026-45866, CVE-2026-45867, CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871, CVE-2026-45872, CVE-2026-45873, CVE-2026-45875, CVE-2026-45877, CVE-2026-45878, CVE-2026-45879, CVE-2026-45880, CVE-2026-45881, CVE-2026-45882, CVE-2026-45883, CVE-2026-45884, CVE-2026-45885, CVE-2026-45886, CVE-2026-45890, CVE-2026-45891, CVE-2026-45893, CVE-2026-45895, CVE-2026-45902, CVE-2026-45904, CVE-2026-45905, CVE-2026-45910, CVE-2026-45912, CVE-2026-45913, CVE-2026-45914, CVE-2026-45915, CVE-2026-45916, CVE-2026-45917, CVE-2026-45919, CVE-2026-45921, CVE-2026-45923, CVE-2026-45928, CVE-2026-45935, CVE-2026-45936, CVE-2026-45938, CVE-2026-45941, CVE-2026-45946, CVE-2026-45947, CVE-2026-45948, CVE-2026-45954, CVE-2026-45957, CVE-2026-45960, CVE-2026-45962, CVE-2026-45964, CVE-2026-45965, CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45972, CVE-2026-45973, CVE-2026-45974, CVE-2026-45976, CVE-2026-45978, CVE-2026-45981, CVE-2026-45982, CVE-2026-45983, CVE-2026-45984, CVE-2026-45988, CVE-2026-46043, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135, CVE-2026-46185, CVE-2026-46195, CVE-2026-46243, CVE-2026-46244, CVE-2026-46246, CVE-2026-46247, CVE-2026-46249, CVE-2026-46250, CVE-2026-46251,CVE-2026-46253, CVE-2026-46254, CVE-2026-46255, CVE-2026-46259, CVE-2026-46260, CVE-2026-46261, CVE-2026-46265, CVE-2026-46266, CVE-2026-46267, CVE-2026-46270, CVE-2026-46289, CVE-2026-46328 Package Information: https://launchpad.net/ubuntu/+source/linux-raspi-realtime/6.8.0-2049.50 . Ubuntu 24.04 LTS fixes multiple security issues in linux-raspi-realtime kernel for critical vulnerabilities.. Linux Kernel Updates, Raspberry Pi Security, Ubuntu Security Notices, Security Vulnerabilities Fix, System Security Patches. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-50306 http://linux.oracle.com/errata/ELSA-2026-50306.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-5.4.17-2136.356.4.2.el7uek.x86_64.rpm kernel-uek-container-5.4.17-2136.356.4.2.el7uek.x86_64.rpm kernel-uek-container-debug-5.4.17-2136.356.4.2.el7uek.x86_64.rpm kernel-uek-debug-5.4.17-2136.356.4.2.el7uek.x86_64.rpm kernel-uek-debug-devel-5.4.17-2136.356.4.2.el7uek.x86_64.rpm kernel-uek-devel-5.4.17-2136.356.4.2.el7uek.x86_64.rpm kernel-uek-doc-5.4.17-2136.356.4.2.el7uek.noarch.rpm kernel-uek-tools-5.4.17-2136.356.4.2.el7uek.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/kernel-uek-5.4.17-2136.356.4.2.el7uek.src.rpm Related CVEs: CVE-2025-10263 Description of changes: [5.4.17-2136.356.4.2] - arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39017592] {CVE-2025-10263} - arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39017592] - ARM: uek: Disable CONFIG_QCOM_FALKOR_ERRATUM_1003 (Boris Ostrovsky) [Orabug: 39017592] - arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39017592] - arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39017592] - arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39017592] [5.4.17-2136.356.4.1] - smb: client: reject userspace cifs.spnego descriptions (Asim Viladi Oglu Manizada) [Orabug: 39463669] [5.4.17-2136.356.4] - tun: free page on build_skb failure in tun_xdp_one() (Weiming Shi) [Orabug: 39429147] - tap: free page on error paths in tap_get_user_xdp() (Weiming Shi) [Orabug: 39429147] - tun: free page on short-frame rejection in tun_xdp_one() (Weiming Shi) [Orabug: 39429147] [5.4.17-2136.356.3] - ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) [Orabug: 39384275,39391459] {CVE-2026-46333} - net: skbuff: propagateshared-frag marker through frag-transfer helpers (Hyunwoo Kim) [Orabug: 39368828,39441326] {CVE-2026-43503,CVE-2026-46300} - net: skbuff: preserve shared-frag marker during coalescing (William Bowling) [Orabug: 39368828] {CVE-2026-46300} [5.4.17-2136.356.2] - nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (Jeff Layton) [Orabug: 39167617,39368718] {CVE-2026-31402} - scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (Maurizio Lombardi) [Orabug: 38985173,39368732] {CVE-2026-23216} - scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (Maurizio Lombardi) [Orabug: 38970455,39368774] {CVE-2026-23193} - xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) [Orabug: 39334580,39367147] {CVE-2026-43284} - x86/CPU/AMD: Add a fix for AMD-SB-7052 (Prathyushi Nangia) [Orabug: 39218897] {CVE-2025-54518} [5.4.17-2136.356.1] - arm64/kvm: Include linux/random.h in trng.c (Siddh Raman Pant) [Orabug: 39327096] - i2c: designware: Disable TX_EMPTY irq while waiting for block length byte (Tam Nguyen) [Orabug: 39174662] - i2c: designware: Handle invalid SMBus block data response length value (Tam Nguyen) [Orabug: 39174662] - i2c: designware: fix __i2c_dw_disable() in case master is holding SCL low (Yann Sionneau) [Orabug: 39174662] [5.4.17-2136.355.3] - crypto: algif_aead - Fix minimum RX size check for decryption (Herbert Xu) [Orabug: 39250687,39331106] {CVE-2026-43077} - crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl (Herbert Xu) [Orabug: 39250687,39331111] {CVE-2026-43078} - crypto: authencesn - Fix src offset when decrypting in-place (Herbert Xu) [Orabug: 39250687] - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (Herbert Xu) [Orabug: 39250687,39300911] {CVE-2026-43033} - crypto: authenc - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250687] - crypto: algif_aead - snapshot IV for async AEAD requests (Douya Le) [Orabug: 39250687,39452217] {CVE-2026-46028} - crypto: algif_aead -Revert to operating out-of-place (Herbert Xu) [Orabug: 39250687,39283868,39292250] {CVE-2026-31431} - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (Eric Biggers) [Orabug: 39250687] {CVE-2026-31431} - crypto: scatterwalk - Backport memcpy_sglist() (Eric Biggers) [Orabug: 39250687] - crypto: doc - fix kernel-doc notation in chacha.c and af_alg.c (Randy Dunlap) [Orabug: 39250687] [5.4.17-2136.355.2] - Revert "rds: Drop rds conn in connect worker if not in down state." (Alok Tiwari) [Orabug: 39253770] - x86/CPU: Fix FPDSS on Zen1 (Siddh Raman Pant) [Orabug: 39241225,39273723] {CVE-2026-31628} - SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (Joshua Rogers) [Orabug: 38852342] {CVE-2025-71120} [5.4.17-2136.355.1] - net/sched: Enforce that teql can only be used as root qdisc (Jamal Hadi Salim) [Orabug: 38930950] {CVE-2026-23074} [5.4.17-2136.354.4] - macvlan: fix possible UAF in macvlan_forward_source() (Eric Dumazet) [Orabug: 38887731] {CVE-2026-23001} - macvlan: Use 'hash' iterators to simplify code (Christophe Jaillet) [Orabug: 38887731] {CVE-2026-23001} - macvlan: Add nodst option to macvlan type source (Jethro Beekman) [Orabug: 38887731] {CVE-2026-23001} - macvlan: observe an RCU grace period in macvlan_common_newlink() error path (Eric Dumazet) [Orabug: 38970510,39188399] {CVE-2026-23209,CVE-2026-23273} - macvlan: fix error recovery in macvlan_common_newlink() (Eric Dumazet) [Orabug: 38970510] {CVE-2026-23209} _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-50305 http://linux.oracle.com/errata/ELSA-2026-50305.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-core-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-debug-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-debug-core-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-debug-devel-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-debug-modules-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-debug-modules-extra-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-devel-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-doc-5.15.0-321.202.5.1.el9uek.noarch.rpm kernel-uek-modules-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-modules-extra-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-container-5.15.0-321.202.5.1.el9uek.x86_64.rpm kernel-uek-container-debug-5.15.0-321.202.5.1.el9uek.x86_64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/kernel-uek-5.15.0-321.202.5.1.el9uek.src.rpm Related CVEs: CVE-2025-10263 Description of changes: [5.15.0-321.202.5.1] - arm64: errata: Mitigate TLBI errata on various Arm CPUs (Mark Rutland) [Orabug: 39017590] {CVE-2025-10263} - arm64: tlb: Add ARM64_WORKAROUND_REPEAT_TLBI_SYNC (Mark Rutland) [Orabug: 39017590] - ARM: uek: Disable CONFIG_NVIDIA_CARMEL_CNP_ERRATUM (Boris Ostrovsky) [Orabug: 39017590] - arm64: tlb: allow XZR argument to TLBI ops (Mark Rutland) [Orabug: 39017590] - arm64: cputype: Add C1-Premium definitions (Mark Rutland) [Orabug: 39017590] - arm64: cputype: Add C1-Ultra definitions (Mark Rutland) [Orabug: 39017590] _______________________________________________ El-errata mailing list
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8200-3 May 11, 2026 linux-raspi, linux-raspi-5.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-raspi: Linux kernel for Raspberry Pi systems - linux-raspi-5.4: Linux kernel for Raspberry Pi systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Cryptographic API; - GPU drivers; - I2C subsystem; - Network traffic control; (CVE-2022-49046, CVE-2024-46816, CVE-2025-37849, CVE-2026-23060, CVE-2026-23074) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1140-raspi 5.4.0-1140.153 Available with Ubuntu Pro linux-image-raspi 5.4.0.1140.171 Available with Ubuntu Pro linux-image-raspi-5.4 5.4.0.1140.171 Available with Ubuntu Pro linux-image-raspi2 5.4.0.1140.171 Available with Ubuntu Pro Ubuntu 18.04 LTS linux-image-5.4.0-1140-raspi 5.4.0-1140.153~18.04.1 Available with Ubuntu Pro linux-image-raspi-5.4 5.4.0.1140.153~18.04.1 Available with Ubuntu Pro linux-image-raspi-hwe-18.04 5.4.0.1140.153~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Dueto an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8200-3 https://ubuntu.com/security/notices/USN-8200-2 https://ubuntu.com/security/notices/USN-8200-1 CVE-2022-49046, CVE-2024-46816, CVE-2025-37849, CVE-2026-23060, CVE-2026-23074 . Several security issues fixed in the Linux kernel for Raspberry Pi users, ensuring enhanced system security.. Linux kernel security, Raspberry Pi updates, Ubuntu security advisories. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7789-2 October 08, 2025 linux-raspi vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-raspi: Linux kernel for Raspberry Pi systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - ACPI drivers; - Android drivers; - Bluetooth drivers; - Bus devices; - Clock framework and drivers; - CPU frequency scaling framework; - Hardware crypto device drivers; - DMA engine subsystem; - EDAC drivers; - Arm Firmware Framework for ARMv8-A(FFA); - FPGA Framework; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - HW tracing; - InfiniBand drivers; - IOMMU subsystem; - Multiple devices driver; - Media drivers; - VMware VMCI Driver; - MTD block device drivers; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - NVDIMM (Non-Volatile Memory Device) drivers; - NVME drivers; - NVMEM (Non Volatile Memory) drivers; - PCI subsystem; - Amlogic Meson DDR PMU; - NI-700 PMU driver; - PHY drivers; - Pin controllers subsystem; - x86 platform drivers; - PTP clock framework; - SCSI subsystem; - ASPEED SoC drivers; - SPI subsystem; - TCM subsystem; - Thunderbolt and USB4 drivers; - TTY drivers; - UFS subsystem; - USB core drivers; - USB Gadget drivers; - Renesas USBHS Controller drivers; - USB Type-C Port Controller Manager driver; - VFIO drivers; - Virtio Host (VHOST) subsystem; - Backlight driver; - Framebuffer layer; - Virtio drivers; - BTRFS file system; - EROFS file system; - F2FS file system; - File systems infrastructure; - Network file systems library; - NTFS3 file system; - SMB network file system; - Codetag library; - BPF subsystem; - LZO compression library; - Mellanox drivers; - IPv4 networking; - Bluetooth subsystem; - Network sockets; - XFRM subsystem; - Digital Audio (PCM) driver; - Tracing infrastructure; - io_uring subsystem; - Padata parallel execution mechanism; - DVFS energy model driver; - Restartable seuqences system call mechanism; - Timer subsystem; - Memory management; - KASAN memory debugging framework; - CAN network layer; - Networking core; - IPv6 networking; - Netfilter; - NetLabel subsystem; - Open vSwitch; - Network traffic control; - TIPC protocol; - TLS protocol; - ALSA framework; - sma1307 audio codecs; - Intel ASoC drivers; - MediaTek ASoC drivers; - USB sound devices; (CVE-2025-38081, CVE-2025-38142, CVE-2025-38157, CVE-2025-38174, CVE-2025-38156, CVE-2025-38044, CVE-2025-38414, CVE-2025-38041, CVE-2025-38124, CVE-2025-38122, CVE-2025-38285, CVE-2025-38317, CVE-2025-38159, CVE-2025-38352, CVE-2025-38117, CVE-2025-38040, CVE-2025-38292, CVE-2025-38301, CVE-2025-38149, CVE-2025-38299, CVE-2025-38116, CVE-2025-38100, CVE-2025-38107, CVE-2025-38063, CVE-2025-38069, CVE-2025-38130, CVE-2025-38032, CVE-2025-38113, CVE-2025-38287, CVE-2025-38138, CVE-2025-38004, CVE-2025-38097, CVE-2025-38270, CVE-2025-38311, CVE-2025-38499, CVE-2025-38050, CVE-2025-38064, CVE-2025-38278, CVE-2025-38297, CVE-2025-38091, CVE-2025-38065, CVE-2025-38114, CVE-2025-38048, CVE-2025-38096, CVE-2025-38112, CVE-2025-38148, CVE-2025-38101, CVE-2025-38062, CVE-2025-38057, CVE-2025-38029, CVE-2025-38105, CVE-2025-38277, CVE-2025-38053, CVE-2025-38302, CVE-2025-38169, CVE-2025-38307, CVE-2025-38153, CVE-2025-38106, CVE-2025-38293, CVE-2025-38267, CVE-2025-38314,CVE-2025-38291, CVE-2025-38284, CVE-2025-38141, CVE-2025-38052, CVE-2025-38079, CVE-2025-38088, CVE-2025-38164, CVE-2025-38288, CVE-2025-38289, CVE-2025-38074, CVE-2025-38073, CVE-2025-38274, CVE-2025-38167, CVE-2025-38129, CVE-2025-38082, CVE-2025-38109, CVE-2025-38003, CVE-2025-38042, CVE-2025-38319, CVE-2025-38165, CVE-2025-38102, CVE-2025-38045, CVE-2025-38154, CVE-2025-38127, CVE-2025-38034, CVE-2025-38051, CVE-2025-38143, CVE-2025-38061, CVE-2025-38119, CVE-2025-38077, CVE-2025-38115, CVE-2025-38175, CVE-2025-38147, CVE-2025-38172, CVE-2025-38176, CVE-2025-38269, CVE-2025-38126, CVE-2025-38131, CVE-2025-38296, CVE-2025-38170, CVE-2025-38110, CVE-2025-38111, CVE-2025-38295, CVE-2025-38072, CVE-2025-38168, CVE-2025-38098, CVE-2025-38160, CVE-2025-38125, CVE-2025-38054, CVE-2025-38286, CVE-2025-38310, CVE-2025-38162, CVE-2025-38135, CVE-2025-38161, CVE-2025-38055, CVE-2025-38066, CVE-2025-38318, CVE-2025-38173, CVE-2025-38033, CVE-2025-38281, CVE-2025-38140, CVE-2025-38146, CVE-2025-38305, CVE-2025-38103, CVE-2025-38080, CVE-2025-38068, CVE-2025-38037, CVE-2025-38043, CVE-2025-38272, CVE-2025-38137, CVE-2025-38279, CVE-2025-38275, CVE-2025-38151, CVE-2025-38123, CVE-2025-38158, CVE-2025-38268, CVE-2025-38136, CVE-2025-38132, CVE-2025-38120, CVE-2025-38047, CVE-2025-38304, CVE-2025-38298, CVE-2025-38265, CVE-2025-38134, CVE-2025-38128, CVE-2025-38118, CVE-2025-38058, CVE-2025-38303, CVE-2025-38316, CVE-2025-38092, CVE-2025-38163, CVE-2025-38155, CVE-2025-38145, CVE-2025-38280, CVE-2025-38076, CVE-2025-38031, CVE-2025-38306, CVE-2025-38078, CVE-2025-38035, CVE-2025-38315, CVE-2025-38300, CVE-2025-38283, CVE-2025-38059, CVE-2025-38312, CVE-2025-38071, CVE-2025-38294, CVE-2025-38036, CVE-2025-38498, CVE-2025-38099, CVE-2025-38070, CVE-2025-38166, CVE-2025-38060, CVE-2025-38282, CVE-2025-38313, CVE-2025-38038, CVE-2025-38290, CVE-2025-39890, CVE-2025-38415, CVE-2025-38039, CVE-2025-38067, CVE-2025-38075, CVE-2025-38108, CVE-2025-38139) Update instructions: The problem can be corrected by updating your system tothe following package versions: Ubuntu 25.04 linux-image-6.14.0-1014-raspi 6.14.0-1014.14 linux-image-raspi 6.14.0-1014.14 linux-image-raspi-6.14 6.14.0-1014.14 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7789-2 https://ubuntu.com/security/notices/USN-7789-1 CVE-2025-38003, CVE-2025-38004, CVE-2025-38029, CVE-2025-38031, CVE-2025-38032, CVE-2025-38033, CVE-2025-38034, CVE-2025-38035, CVE-2025-38036, CVE-2025-38037, CVE-2025-38038, CVE-2025-38039, CVE-2025-38040, CVE-2025-38041, CVE-2025-38042, CVE-2025-38043, CVE-2025-38044, CVE-2025-38045, CVE-2025-38047, CVE-2025-38048, CVE-2025-38050, CVE-2025-38051, CVE-2025-38052, CVE-2025-38053, CVE-2025-38054, CVE-2025-38055, CVE-2025-38057, CVE-2025-38058, CVE-2025-38059, CVE-2025-38060, CVE-2025-38061, CVE-2025-38062, CVE-2025-38063, CVE-2025-38064, CVE-2025-38065, CVE-2025-38066, CVE-2025-38067, CVE-2025-38068, CVE-2025-38069, CVE-2025-38070, CVE-2025-38071, CVE-2025-38072, CVE-2025-38073, CVE-2025-38074, CVE-2025-38075, CVE-2025-38076, CVE-2025-38077, CVE-2025-38078, CVE-2025-38079, CVE-2025-38080, CVE-2025-38081, CVE-2025-38082, CVE-2025-38088, CVE-2025-38091, CVE-2025-38092, CVE-2025-38096, CVE-2025-38097, CVE-2025-38098, CVE-2025-38099, CVE-2025-38100, CVE-2025-38101, CVE-2025-38102, CVE-2025-38103, CVE-2025-38105, CVE-2025-38106, CVE-2025-38107, CVE-2025-38108, CVE-2025-38109, CVE-2025-38110, CVE-2025-38111, CVE-2025-38112, CVE-2025-38113, CVE-2025-38114, CVE-2025-38115,CVE-2025-38116, CVE-2025-38117, CVE-2025-38118, CVE-2025-38119, CVE-2025-38120, CVE-2025-38122, CVE-2025-38123, CVE-2025-38124, CVE-2025-38125, CVE-2025-38126, CVE-2025-38127, CVE-2025-38128, CVE-2025-38129, CVE-2025-38130, CVE-2025-38131, CVE-2025-38132, CVE-2025-38134, CVE-2025-38135, CVE-2025-38136, CVE-2025-38137, CVE-2025-38138, CVE-2025-38139, CVE-2025-38140, CVE-2025-38141, CVE-2025-38142, CVE-2025-38143, CVE-2025-38145, CVE-2025-38146, CVE-2025-38147, CVE-2025-38148, CVE-2025-38149, CVE-2025-38151, CVE-2025-38153, CVE-2025-38154, CVE-2025-38155, CVE-2025-38156, CVE-2025-38157, CVE-2025-38158, CVE-2025-38159, CVE-2025-38160, CVE-2025-38161, CVE-2025-38162, CVE-2025-38163, CVE-2025-38164, CVE-2025-38165, CVE-2025-38166, CVE-2025-38167, CVE-2025-38168, CVE-2025-38169, CVE-2025-38170, CVE-2025-38172, CVE-2025-38173, CVE-2025-38174, CVE-2025-38175, CVE-2025-38176, CVE-2025-38265, CVE-2025-38267, CVE-2025-38268, CVE-2025-38269, CVE-2025-38270, CVE-2025-38272, CVE-2025-38274, CVE-2025-38275, CVE-2025-38277, CVE-2025-38278, CVE-2025-38279, CVE-2025-38280, CVE-2025-38281, CVE-2025-38282, CVE-2025-38283, CVE-2025-38284, CVE-2025-38285, CVE-2025-38286, CVE-2025-38287, CVE-2025-38288, CVE-2025-38289, CVE-2025-38290, CVE-2025-38291, CVE-2025-38292, CVE-2025-38293, CVE-2025-38294, CVE-2025-38295, CVE-2025-38296, CVE-2025-38297, CVE-2025-38298, CVE-2025-38299, CVE-2025-38300, CVE-2025-38301, CVE-2025-38302, CVE-2025-38303, CVE-2025-38304, CVE-2025-38305, CVE-2025-38306, CVE-2025-38307, CVE-2025-38310, CVE-2025-38311, CVE-2025-38312, CVE-2025-38313, CVE-2025-38314, CVE-2025-38315, CVE-2025-38316, CVE-2025-38317, CVE-2025-38318, CVE-2025-38319, CVE-2025-38352, CVE-2025-38414, CVE-2025-38415, CVE-2025-38498, CVE-2025-38499, CVE-2025-39890 Package Information: https://launchpad.net/ubuntu/+source/linux-raspi/6.14.0-1014.14 . Discover recent security fixes for the Linux kernel on Ubuntu 25.04, addressing several critical issues for Raspberry Pi systems.. Ubuntuupdates, Linux kernel patch, Raspberry Pi security, ARM architecture fixes, system vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7774-1 September 25, 2025 linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle, linux-raspi, linux-riscv-5.15, linux-xilinx-zynqmp vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-intel-iotg: Linux kernel for Intel IoT platforms - linux-lowlatency: Linux low latency kernel - linux-nvidia: Linux kernel for NVIDIA systems - linux-nvidia-tegra: Linux kernel for NVIDIA Tegra systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi: Linux kernel for Raspberry Pi systems - linux-xilinx-zynqmp: Linux kernel for Xilinx ZynqMP processors - linux-aws-5.15: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.15: Linux hardware enablement (HWE) kernel - linux-ibm-5.15: Linux kernel for IBM cloud systems - linux-intel-iotg-5.15: Linux kernel for Intel IoT platforms - linux-lowlatency-hwe-5.15: Linux low latency kernel - linux-nvidia-tegra-5.15: Linux kernel for NVIDIA Tegra systems - linux-riscv-5.15: Linux kernel for RISC-V systems Details: Severalsecurity issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - x86 architecture; - ACPI drivers; - Serial ATA and Parallel ATA drivers; - Drivers core; - ATA over ethernet (AOE) driver; - Network block device driver; - Bus devices; - Clock framework and drivers; - Hardware crypto device drivers; - DMA engine subsystem; - EDAC drivers; - GPU drivers; - HID subsystem; - InfiniBand drivers; - Input Device (Miscellaneous) drivers; - Multiple devices driver; - Media drivers; - VMware VMCI Driver; - MMC subsystem; - MTD block device drivers; - Network drivers; - Pin controllers subsystem; - x86 platform drivers; - PTP clock framework; - RapidIO drivers; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - S/390 drivers; - SCSI subsystem; - ASPEED SoC drivers; - TCM subsystem; - Thermal drivers; - Thunderbolt and USB4 drivers; - TTY drivers; - UFS subsystem; - USB Gadget drivers; - Renesas USBHS Controller drivers; - USB Type-C support driver; - Virtio Host (VHOST) subsystem; - Backlight driver; - Framebuffer layer; - BTRFS file system; - File systems infrastructure; - Ext4 file system; - F2FS file system; - JFFS2 file system; - JFS file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NTFS3 file system; - DRM display driver; - Memory Management; - Mellanox drivers; - Memory management; - Netfilter; - Network sockets; - IPC subsystem; - BPF subsystem; - Perf events; - Kernel exit() syscall; - Restartable seuqences system call mechanism; - Timer subsystem; - Tracing infrastructure; - Appletalk network protocol; - Asynchronous Transfer Mode (ATM) subsystem; - Networking core; - IPv6 networking; - MultiProtocol Label Switching driver; - NetLabel subsystem; - Netlink; - NFC subsystem; - Open vSwitch; - Rose network layer; - RxRPC session sockets; - Network traffic control; - TIPC protocol; - VMware vSockets driver; - USB sound devices; (CVE-2025-38465, CVE-2025-38386, CVE-2025-38273, CVE-2025-38227, CVE-2025-38107, CVE-2025-37958, CVE-2025-38371, CVE-2025-38328, CVE-2025-38348, CVE-2025-38100, CVE-2025-38336, CVE-2025-38420, CVE-2025-38154, CVE-2025-38542, CVE-2025-38222, CVE-2025-38406, CVE-2025-37948, CVE-2025-38112, CVE-2025-38145, CVE-2025-38163, CVE-2025-38464, CVE-2025-38085, CVE-2025-38342, CVE-2025-38310, CVE-2025-38326, CVE-2025-38418, CVE-2025-38362, CVE-2025-38412, CVE-2025-38219, CVE-2025-38332, CVE-2025-38387, CVE-2025-38262, CVE-2025-38157, CVE-2025-38514, CVE-2025-38466, CVE-2025-38313, CVE-2025-38159, CVE-2024-44939, CVE-2025-38352, CVE-2025-38459, CVE-2025-38419, CVE-2025-38086, CVE-2025-38298, CVE-2025-38146, CVE-2025-38181, CVE-2025-38448, CVE-2025-38231, CVE-2025-38461, CVE-2025-38251, CVE-2025-38391, CVE-2025-38515, CVE-2024-26726, CVE-2025-38462, CVE-2025-38416, CVE-2025-38280, CVE-2025-38226, CVE-2025-38211, CVE-2025-38120, CVE-2025-38377, CVE-2025-38147, CVE-2025-38204, CVE-2025-38345, CVE-2025-38424, CVE-2025-38203, CVE-2025-38443, CVE-2025-38197, CVE-2025-38067, CVE-2025-38400, CVE-2025-38229, CVE-2025-38108, CVE-2025-38319, CVE-2025-38445, CVE-2025-38212, CVE-2025-38184, CVE-2025-38363, CVE-2025-38160, CVE-2024-57883, CVE-2025-38441, CVE-2025-38320, CVE-2025-38393, CVE-2025-38200, CVE-2025-38467, CVE-2025-38444, CVE-2025-38194, CVE-2025-38460, CVE-2025-38167, CVE-2025-38428, CVE-2025-38312, CVE-2025-38111, CVE-2025-38498, CVE-2025-38135, CVE-2025-38237, CVE-2025-38457, CVE-2025-38401, CVE-2025-38206, CVE-2025-38293, CVE-2025-38143, CVE-2025-38161, CVE-2025-38136, CVE-2022-48703, CVE-2025-38513, CVE-2025-38430, CVE-2025-38384, CVE-2025-38346, CVE-2025-38337, CVE-2025-38088, CVE-2025-38257, CVE-2025-38395, CVE-2025-38153, CVE-2025-38263, CVE-2025-38218, CVE-2024-26775, CVE-2025-38305, CVE-2025-38119, CVE-2025-38389,CVE-2025-38102, CVE-2025-38074, CVE-2025-38173, CVE-2025-38138, CVE-2025-38103, CVE-2025-38286, CVE-2025-38458, CVE-2025-38174, CVE-2025-38245, CVE-2025-38084, CVE-2025-38415, CVE-2025-38516, CVE-2025-38090, CVE-2025-38439, CVE-2025-38403, CVE-2025-38115, CVE-2025-38344, CVE-2025-38410, CVE-2025-38375, CVE-2025-37963, CVE-2025-38249, CVE-2025-38324, CVE-2025-38122, CVE-2025-38540, CVE-2025-38399, CVE-2025-21888, CVE-2025-38285) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1045-nvidia-tegra 5.15.0-1045.45 linux-image-5.15.0-1045-nvidia-tegra-rt 5.15.0-1045.45 linux-image-5.15.0-1056-xilinx-zynqmp 5.15.0-1056.60 linux-image-5.15.0-1075-gkeop 5.15.0-1075.83 linux-image-5.15.0-1086-ibm 5.15.0-1086.89 linux-image-5.15.0-1086-raspi 5.15.0-1086.89 linux-image-5.15.0-1087-intel-iotg 5.15.0-1087.93 linux-image-5.15.0-1087-nvidia 5.15.0-1087.88 linux-image-5.15.0-1087-nvidia-lowlatency 5.15.0-1087.88 linux-image-5.15.0-1089-gke 5.15.0-1089.95 linux-image-5.15.0-1090-oracle 5.15.0-1090.96 linux-image-5.15.0-1092-aws 5.15.0-1092.99 linux-image-5.15.0-1092-aws-64k 5.15.0-1092.99 linux-image-5.15.0-1092-gcp 5.15.0-1092.101 linux-image-5.15.0-156-generic 5.15.0-156.166 linux-image-5.15.0-156-generic-64k 5.15.0-156.166 linux-image-5.15.0-156-generic-lpae 5.15.0-156.166 linux-image-5.15.0-156-lowlatency 5.15.0-156.166 linux-image-5.15.0-156-lowlatency-64k 5.15.0-156.166 linux-image-aws-5.15 5.15.0.1092.95 linux-image-aws-64k-5.15 5.15.0.1092.95 linux-image-aws-64k-lts-22.04 5.15.0.1092.95 linux-image-aws-lts-22.04 5.15.0.1092.95 linux-image-gcp-5.15 5.15.0.1092.88 linux-image-gcp-lts-22.04 5.15.0.1092.88 linux-image-generic 5.15.0.156.154 linux-image-generic-5.15 5.15.0.156.154 linux-image-generic-64k 5.15.0.156.154 linux-image-generic-64k-5.15 5.15.0.156.154 linux-image-generic-lpae 5.15.0.156.154 linux-image-generic-lpae-5.15 5.15.0.156.154 linux-image-gke 5.15.0.1089.88 linux-image-gke-5.15 5.15.0.1089.88 linux-image-gkeop 5.15.0.1075.74 linux-image-gkeop-5.15 5.15.0.1075.74 linux-image-ibm 5.15.0.1086.82 linux-image-ibm-5.15 5.15.0.1086.82 linux-image-intel-iotg 5.15.0.1087.87 linux-image-intel-iotg-5.15 5.15.0.1087.87 linux-image-lowlatency 5.15.0.156.135 linux-image-lowlatency-5.15 5.15.0.156.135 linux-image-lowlatency-64k 5.15.0.156.135 linux-image-lowlatency-64k-5.15 5.15.0.156.135 linux-image-nvidia 5.15.0.1087.87 linux-image-nvidia-5.15 5.15.0.1087.87 linux-image-nvidia-lowlatency 5.15.0.1087.87 linux-image-nvidia-lowlatency-5.15 5.15.0.1087.87 linux-image-nvidia-tegra 5.15.0.1045.45 linux-image-nvidia-tegra-5.15 5.15.0.1045.45 linux-image-nvidia-tegra-rt 5.15.0.1045.45 linux-image-nvidia-tegra-rt-5.15 5.15.0.1045.45 linux-image-oracle-5.15 5.15.0.1090.86 linux-image-oracle-lts-22.04 5.15.0.1090.86 linux-image-raspi 5.15.0.1086.84 linux-image-raspi-5.15 5.15.0.1086.84 linux-image-raspi-nolpae 5.15.0.1086.84 linux-image-virtual 5.15.0.156.154 linux-image-virtual-5.15 5.15.0.156.154 linux-image-xilinx-zynqmp 5.15.0.1056.59 linux-image-xilinx-zynqmp-5.15 5.15.0.1056.59 Ubuntu 20.04 LTS linux-image-5.15.0-1045-nvidia-tegra 5.15.0-1045.45~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-1045-nvidia-tegra-rt 5.15.0-1045.45~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-1086-ibm 5.15.0-1086.89~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-1087-generic 5.15.0-1087.91~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-1087-intel-iotg 5.15.0-1087.93~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-1092-aws 5.15.0-1092.99~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-1092-gcp 5.15.0-1092.101~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-156-generic 5.15.0-156.166~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-156-generic-64k 5.15.0-156.166~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-156-generic-lpae 5.15.0-156.166~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-156-lowlatency 5.15.0-156.166~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-156-lowlatency-64k 5.15.0-156.166~20.04.1 Available with Ubuntu Pro linux-image-aws 5.15.0.1092.99~20.04.1 Available with Ubuntu Pro linux-image-aws-5.15 5.15.0.1092.99~20.04.1 Available with Ubuntu Pro linux-image-gcp 5.15.0.1092.101~20.04.1 Available with Ubuntu Pro linux-image-gcp-5.15 5.15.0.1092.101~20.04.1 Available with Ubuntu Pro linux-image-generic 5.15.0.1087.91~20.04.1 Available with Ubuntu Pro linux-image-generic-5.15 5.15.0.1087.91~20.04.1 Available with Ubuntu Pro linux-image-generic-64k-5.15 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-generic-64k-hwe-20.04 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-generic-hwe-20.04 5.15.0.1087.91~20.04.1 Available with Ubuntu Pro linux-image-generic-lpae-5.15 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-generic-lpae-hwe-20.04 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-ibm 5.15.0.1086.89~20.04.1 Available with Ubuntu Pro linux-image-ibm-5.15 5.15.0.1086.89~20.04.1 Available with Ubuntu Pro linux-image-intel 5.15.0.1087.93~20.04.1 Available with Ubuntu Pro linux-image-intel-iotg 5.15.0.1087.93~20.04.1 Available with Ubuntu Pro linux-image-intel-iotg-5.15 5.15.0.1087.93~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-5.15 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-64k-5.15 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-64k-hwe-20.04 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-hwe-20.04 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-nvidia-tegra 5.15.0.1045.45~20.04.1 Available with Ubuntu Pro linux-image-nvidia-tegra-5.15 5.15.0.1045.45~20.04.1 Available with Ubuntu Pro linux-image-nvidia-tegra-rt 5.15.0.1045.45~20.04.1 Available with Ubuntu Pro linux-image-nvidia-tegra-rt-5.15 5.15.0.1045.45~20.04.1 Available with Ubuntu Pro linux-image-oem-20.04 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-oem-20.04b 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-oem-20.04c 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-oem-20.04d 5.15.0.156.166~20.04.1 Available with Ubuntu Pro linux-image-virtual 5.15.0.1087.91~20.04.1 Available with Ubuntu Pro linux-image-virtual-5.15 5.15.0.1087.91~20.04.1 Available with Ubuntu Pro linux-image-virtual-hwe-20.04 5.15.0.1087.91~20.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7774-1 CVE-2022-48703, CVE-2024-26726, CVE-2024-26775, CVE-2024-44939, CVE-2024-57883, CVE-2025-21888, CVE-2025-37948, CVE-2025-37958, CVE-2025-37963, CVE-2025-38067, CVE-2025-38074, CVE-2025-38084, CVE-2025-38085, CVE-2025-38086, CVE-2025-38088, CVE-2025-38090, CVE-2025-38100, CVE-2025-38102, CVE-2025-38103, CVE-2025-38107, CVE-2025-38108, CVE-2025-38111, CVE-2025-38112, CVE-2025-38115, CVE-2025-38119, CVE-2025-38120, CVE-2025-38122, CVE-2025-38135, CVE-2025-38136, CVE-2025-38138, CVE-2025-38143, CVE-2025-38145, CVE-2025-38146, CVE-2025-38147, CVE-2025-38153, CVE-2025-38154, CVE-2025-38157, CVE-2025-38159, CVE-2025-38160, CVE-2025-38161, CVE-2025-38163, CVE-2025-38167, CVE-2025-38173, CVE-2025-38174, CVE-2025-38181, CVE-2025-38184, CVE-2025-38194, CVE-2025-38197, CVE-2025-38200, CVE-2025-38203, CVE-2025-38204, CVE-2025-38206, CVE-2025-38211, CVE-2025-38212, CVE-2025-38218, CVE-2025-38219, CVE-2025-38222, CVE-2025-38226,CVE-2025-38227, CVE-2025-38229, CVE-2025-38231, CVE-2025-38237, CVE-2025-38245, CVE-2025-38249, CVE-2025-38251, CVE-2025-38257, CVE-2025-38262, CVE-2025-38263, CVE-2025-38273, CVE-2025-38280, CVE-2025-38285, CVE-2025-38286, CVE-2025-38293, CVE-2025-38298, CVE-2025-38305, CVE-2025-38310, CVE-2025-38312, CVE-2025-38313, CVE-2025-38319, CVE-2025-38320, CVE-2025-38324, CVE-2025-38326, CVE-2025-38328, CVE-2025-38332, CVE-2025-38336, CVE-2025-38337, CVE-2025-38342, CVE-2025-38344, CVE-2025-38345, CVE-2025-38346, CVE-2025-38348, CVE-2025-38352, CVE-2025-38362, CVE-2025-38363, CVE-2025-38371, CVE-2025-38375, CVE-2025-38377, CVE-2025-38384, CVE-2025-38386, CVE-2025-38387, CVE-2025-38389, CVE-2025-38391, CVE-2025-38393, CVE-2025-38395, CVE-2025-38399, CVE-2025-38400, CVE-2025-38401, CVE-2025-38403, CVE-2025-38406, CVE-2025-38410, CVE-2025-38412, CVE-2025-38415, CVE-2025-38416, CVE-2025-38418, CVE-2025-38419, CVE-2025-38420, CVE-2025-38424, CVE-2025-38428, CVE-2025-38430, CVE-2025-38439, CVE-2025-38441, CVE-2025-38443, CVE-2025-38444, CVE-2025-38445, CVE-2025-38448, CVE-2025-38457, CVE-2025-38458, CVE-2025-38459, CVE-2025-38460, CVE-2025-38461, CVE-2025-38462, CVE-2025-38464, CVE-2025-38465, CVE-2025-38466, CVE-2025-38467, CVE-2025-38498, CVE-2025-38513, CVE-2025-38514, CVE-2025-38515, CVE-2025-38516, CVE-2025-38540, CVE-2025-38542 Package Information: https://launchpad.net/ubuntu/+source/linux-aws/5.15.0-1092.99 https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1075.83 https://launchpad.net/ubuntu/+source/linux-ibm/5.15.0-1086.89 https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1087.93 https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1087.88 https://launchpad.net/ubuntu/+source/linux-nvidia-tegra/5.15.0-1045.45 https://launchpad.net/ubuntu/+source/linux-oracle/5.15.0-1090.96 https://launchpad.net/ubuntu/+source/linux-xilinx-zynqmp/5.15.0-1056.60 . Urgent vulnerabilities within the Ubuntu Linux kernel necessitate promptpatches to prevent potential breaches.. Ubuntu Kernel Security, System Compromise, Linux Kernel Flaws. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7308-1 February 27, 2025 linux-aws vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-aws: Linux kernel for Amazon Web Services (AWS) systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - x86 architecture; - Block layer subsystem; - ACPI drivers; - GPU drivers; - HID subsystem; - I2C subsystem; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - IRQ chip drivers; - Multiple devices driver; - Media drivers; - Network drivers; - STMicroelectronics network drivers; - Parport drivers; - Pin controllers subsystem; - Direct Digital Synthesis drivers; - TCM subsystem; - TTY drivers; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - USB Type-C support driver; - USB Type-C Connector System Software Interface driver; - BTRFS file system; - File systems infrastructure; - Network file system (NFS) client; - NILFS2 file system; - NTFS3 file system; - SMB network file system; - User-space API (UAPI); - io_uring subsystem; - BPF subsystem; - Timer substystem drivers; - Tracing infrastructure; - Closures library; - Memory management; - Amateur Radio drivers; - Bluetooth subsystem; - Networking core; - IPv4 networking; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - Network traffic control; - SCTP protocol; - VMware vSockets driver; - XFRM subsystem; - Key management; - FireWire sound drivers; - HD-audio driver; - QCOMASoC drivers; - STMicroelectronics SoC drivers; - KVM core; (CVE-2024-50141, CVE-2024-53101, CVE-2024-50301, CVE-2024-50082, CVE-2024-39497, CVE-2024-50245, CVE-2024-50302, CVE-2024-35887, CVE-2024-50205, CVE-2024-50153, CVE-2024-50154, CVE-2024-50279, CVE-2024-50074, CVE-2024-50168, CVE-2024-50128, CVE-2024-53141, CVE-2024-50290, CVE-2024-50292, CVE-2024-50218, CVE-2024-50193, CVE-2024-50209, CVE-2024-53088, CVE-2024-50058, CVE-2024-50116, CVE-2024-50199, CVE-2024-50083, CVE-2024-50265, CVE-2024-53058, CVE-2024-50244, CVE-2024-50195, CVE-2024-41066, CVE-2024-50151, CVE-2024-50229, CVE-2024-42291, CVE-2024-40965, CVE-2024-50160, CVE-2024-53097, CVE-2024-50134, CVE-2024-53164, CVE-2024-50295, CVE-2024-50267, CVE-2024-50251, CVE-2024-50198, CVE-2024-53042, CVE-2024-40953, CVE-2024-50167, CVE-2024-50010, CVE-2024-42252, CVE-2024-53055, CVE-2024-50259, CVE-2024-50110, CVE-2024-50208, CVE-2024-50249, CVE-2024-50148, CVE-2024-50269, CVE-2024-50182, CVE-2024-50115, CVE-2024-50287, CVE-2024-50142, CVE-2024-53103, CVE-2024-50099, CVE-2024-50234, CVE-2024-50282, CVE-2024-50185, CVE-2024-50247, CVE-2024-50257, CVE-2024-50036, CVE-2024-50268, CVE-2024-50127, CVE-2024-50230, CVE-2024-50278, CVE-2024-50273, CVE-2024-26718, CVE-2024-50086, CVE-2024-50262, CVE-2024-50236, CVE-2024-50117, CVE-2024-50237, CVE-2024-53104, CVE-2024-50194, CVE-2024-50192, CVE-2024-53061, CVE-2024-53052, CVE-2024-50202, CVE-2024-41080, CVE-2024-50143, CVE-2023-52913, CVE-2024-50296, CVE-2024-50085, CVE-2024-50196, CVE-2024-50072, CVE-2024-50171, CVE-2024-50103, CVE-2024-50101, CVE-2024-50156, CVE-2024-50201, CVE-2024-50233, CVE-2024-53059, CVE-2024-53066, CVE-2024-53063, CVE-2024-50150, CVE-2024-50131, CVE-2024-50163, CVE-2024-50162, CVE-2024-50299, CVE-2024-50232) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1078-aws 5.15.0-1078.85 linux-image-aws-lts-22.04 5.15.0.1078.80 After a standard system update you need to reboot yourcomputer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7308-1 CVE-2023-52913, CVE-2024-26718, CVE-2024-35887, CVE-2024-39497, CVE-2024-40953, CVE-2024-40965, CVE-2024-41066, CVE-2024-41080, CVE-2024-42252, CVE-2024-42291, CVE-2024-50010, CVE-2024-50036, CVE-2024-50058, CVE-2024-50072, CVE-2024-50074, CVE-2024-50082, CVE-2024-50083, CVE-2024-50085, CVE-2024-50086, CVE-2024-50099, CVE-2024-50101, CVE-2024-50103, CVE-2024-50110, CVE-2024-50115, CVE-2024-50116, CVE-2024-50117, CVE-2024-50127, CVE-2024-50128, CVE-2024-50131, CVE-2024-50134, CVE-2024-50141, CVE-2024-50142, CVE-2024-50143, CVE-2024-50148, CVE-2024-50150, CVE-2024-50151, CVE-2024-50153, CVE-2024-50154, CVE-2024-50156, CVE-2024-50160, CVE-2024-50162, CVE-2024-50163, CVE-2024-50167, CVE-2024-50168, CVE-2024-50171, CVE-2024-50182, CVE-2024-50185, CVE-2024-50192, CVE-2024-50193, CVE-2024-50194, CVE-2024-50195, CVE-2024-50196, CVE-2024-50198, CVE-2024-50199, CVE-2024-50201, CVE-2024-50202, CVE-2024-50205, CVE-2024-50208, CVE-2024-50209, CVE-2024-50218, CVE-2024-50229, CVE-2024-50230, CVE-2024-50232, CVE-2024-50233, CVE-2024-50234, CVE-2024-50236, CVE-2024-50237, CVE-2024-50244, CVE-2024-50245, CVE-2024-50247, CVE-2024-50249, CVE-2024-50251, CVE-2024-50257, CVE-2024-50259, CVE-2024-50262, CVE-2024-50265, CVE-2024-50267, CVE-2024-50268, CVE-2024-50269, CVE-2024-50273, CVE-2024-50278, CVE-2024-50279, CVE-2024-50282, CVE-2024-50287, CVE-2024-50290, CVE-2024-50292, CVE-2024-50295, CVE-2024-50296, CVE-2024-50299, CVE-2024-50301, CVE-2024-50302, CVE-2024-53042, CVE-2024-53052, CVE-2024-53055, CVE-2024-53058, CVE-2024-53059, CVE-2024-53061, CVE-2024-53063, CVE-2024-53066, CVE-2024-53088, CVE-2024-53097, CVE-2024-53101, CVE-2024-53103, CVE-2024-53104, CVE-2024-53141, CVE-2024-53164 Package Information: https://launchpad.net/ubuntu/+source/linux-aws/5.15.0-1078.85 . Debian 11.5 updates tackle various system vulnerabilities and improve overall stability. A restart is required following this update.. Linux Kernel Update, Ubuntu Security Advisory, AWS Kernel Improvements. . Severity: Critical. LinuxSecurity.com Team
The container sles-15-sp4-chost-byos-v20230606-arm64 was updated. The following patches have been included in this update:. SUSE Image Update Advisory: sles-15-sp4-chost-byos-v20230606-arm64 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2023:338-1 Image Tags : sles-15-sp4-chost-byos-v20230606-arm64:20230606 Image Release : Severity : critical Type : security References : 1027519 1127591 1186870 1195633 1199282 1200441 1203141 1204478 1204563 1207410 1208329 1208581 1209094 1209131 1209140 1209237 1209245 1209406 1209550 1209669 1209905 1210089 1210105 1210164 1210298 1210593 1210640 1210649 1210702 1210870 1211144 1211230 1211231 1211232 1211233 1211430 1211604 1211605 1211606 1211607 1211643 CVE-2023-2650 CVE-2023-28319 CVE-2023-28320 CVE-2023-28321 CVE-2023-28322 CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067 CVE-2023-32324 ----------------------------------------------------------------- The container sles-15-sp4-chost-byos-v20230606-arm64 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-feature-2023:2192-1 Released: Fri May 12 12:49:02 2023 Summary: Feature update for python311, python311-pip, python311-setuptools Type: feature Severity: moderate References: This release of python311, python311-pip, python311-setuptools adds the following feature: - Add Python-3.11 to SLE-15-SP4 Python Module (jsc#PED-68, jsc#PED-2634) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2216-1 Released: Tue May 16 11:27:50 2023 Summary: Recommended update for python-packaging Type: recommended Severity: important References: 1186870,1199282 This update for python-packagingfixes the following issues: - Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Add patch to fix testsuite on big-endian targets - Ignore python3.6.2 since the test doesn't support it. - update to 21.3: * Add a pp3-none-any tag * Replace the blank pyparsing 3 exclusion with a 3.0.5 exclusion * Fix a spelling mistake - update to 21.2: * Update documentation entry for 21.1. * Update pin to pyparsing to exclude 3.0.0. * PEP 656: musllinux support * Drop support for Python 2.7, Python 3.4 and Python 3.5 * Replace distutils usage with sysconfig * Add support for zip files * Use cached hash attribute to short-circuit tag equality comparisons * Specify the default value for the 'specifier' argument to 'SpecifierSet' * Proper keyword-only 'warn' argument in packaging.tags * Correctly remove prerelease suffixes from ~= check * Fix type hints for 'Version.post' and 'Version.dev' * Use typing alias 'UnparsedVersion' * Improve type inference * Tighten the return typeo - Add Provides: for python*dist(packaging). (bsc#1186870) - add no-legacyversion-warning.patch to restore compatibility with 20.4 - update to 20.9: * Add support for the ``macosx_10_*_universal2`` platform tags * Introduce ``packaging.utils.parse_wheel_filename()`` and ``parse_sdist_filename()`` - update to 20.8: * Revert back to setuptools for compatibility purposes for some Linux distros * Do not insert an underscore in wheel tags when the interpreter version number is more than 2 digits * Fix flit configuration, to include LICENSE files * Make `intel` a recognized CPU architecture for the `universal` macOS platform tag * Add some missing type hints to `packaging.requirements` * Officially support Python 3.9 * Deprecate the ``LegacyVersion`` and ``LegacySpecifier`` classes * Handle ``OSError`` on non-dynamic executables when attempting to resolve the glibc version string. - update to 20.4: * Canonicalize version before comparing specifiers. * Change type hint for``canonicalize_name`` to return ``packaging.utils.NormalizedName``. This enables the use of static typing tools (like mypy) to detect mixing of normalized and un-normalized names. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2224-1 Released: Wed May 17 09:53:54 2023 Summary: Security update for curl Type: security Severity: important References: 1211230,1211231,1211232,1211233,CVE-2023-28319,CVE-2023-28320,CVE-2023-28321,CVE-2023-28322 This update for curl adds the following feature: Update to version 8.0.1 (jsc#PED-2580) - CVE-2023-28319: use-after-free in SSH sha256 fingerprint check (bsc#1211230). - CVE-2023-28320: siglongjmp race condition (bsc#1211231). - CVE-2023-28321: IDN wildcard matching (bsc#1211232). - CVE-2023-28322: POST-after-PUT confusion (bsc#1211233). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2237-1 Released: Wed May 17 17:10:07 2023 Summary: Recommended update for vim Type: recommended Severity: moderate References: 1211144 This update for vim fixes the following issues: * Make xxd conflict with the previous vim packages to avoid a file conflict during migration (bsc#1211144) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2240-1 Released: Wed May 17 19:56:54 2023 Summary: Recommended update for systemd Type: recommended Severity: moderate References: 1203141,1207410 This update for systemd fixes the following issues: - udev-rules: fix nvme symlink creation on namespace changes (bsc#1207410) - Optimize when hundred workers claim the same symlink with the same priority (bsc#1203141) - Add nss-resolve and systemd-network to Packagehub-Subpackages (MSC-626) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2245-1 Released: Thu May 18 17:01:47 2023 Summary: Recommended update for libzypp, zypper Type: recommended Severity: moderate References: 1127591,1195633,1208329,1209406,1210870 This update for libzypp, zypper fixes the following issues: - Installing local RPM packages fails if /usr/bin/find is not installed (bsc#1195633) - multicurl: propagate ssl settings stored in repo url (bsc#1127591) - MediaCurl: Fix endless loop if wrong credentials are stored in credentials.cat (bsc#1210870) - zypp.conf: Introduce 'download.connect_timeout' [60 sec.] (bsc#1208329) - Teach MediaNetwork to retry on HTTP2 errors. - Fix selecting installed patterns from picklist (bsc#1209406) - man: better explanation of --priority ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2254-1 Released: Fri May 19 15:20:23 2023 Summary: Security update for containerd Type: security Severity: important References: 1210298 This update for containerd fixes the following issues: - Rebuild containerd with a current version of go to catch up on bugfixes and security fixes (bsc#1210298) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2256-1 Released: Fri May 19 15:26:43 2023 Summary: Security update for runc Type: security Severity: important References: 1200441 This update of runc fixes the following issues: - rebuild the package with the go 19.9 secure release (bsc#1200441). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2276-1 Released: Wed May 24 07:54:42 2023 Summary: Recommended update for grub2 Type: recommended Severity: moderate References: 1204563,1208581 This update for grub2 fixes the following issues: - grub2-once: Fix 'sh: terminal_output: command not found' error (bsc#1204563) - Fix PowerVS deployment fails to boot with 90 cores (bsc#1208581) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2279-1 Released: Wed May 24 07:57:53 2023 Summary: Recommended update for dracut Type: recommended Severity: moderate References: 1204478,1210640 This update for dracut fixes the following issues: - Update to version 055+suse.342.g2e6dce8e: fips=1 and separate /boot break s390x (bsc#1204478): * fix(fips): move fips-boot script to pre-pivot * fix(fips): only unmount /boot if it was mounted by the fips module * feat(fips): add progress messages * fix(fips): do not blindly remove /boot * fix(network-legacy): handle do_dhcp calls without arguments (bsc#1210640) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2307-1 Released: Mon May 29 10:29:49 2023 Summary: Recommended update for kbd Type: recommended Severity: low References: 1210702 This update for kbd fixes the following issue: - Add 'ara' vc keymap, 'ara' is slightly better than 'arabic' as it matches the name of its X11 layout counterpart. (bsc#1210702) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2313-1 Released: Tue May 30 09:29:25 2023 Summary: Security update for c-ares Type: security Severity: important References: 1211604,1211605,1211606,1211607,CVE-2023-31124,CVE-2023-31130,CVE-2023-31147,CVE-2023-32067 This update for c-ares fixes the following issues: Update to version 1.19.1: - CVE-2023-32067: 0-byte UDP payload causes Denial of Service (bsc#1211604) - CVE-2023-31147: Insufficient randomness in generation of DNS query IDs (bsc#1211605) - CVE-2023-31130: Buffer Underwrite in ares_inet_net_pton() (bsc#1211606) - CVE-2023-31124: AutoTools does not set CARES_RANDOM_FILE during cross compilation (bsc#1211607) - Fix uninitialized memory warning in test - ares_getaddrinfo() should allow a port of 0 - Fix memory leak in ares_send() on error - Fix comment style in ares_data.h - Fix typo in ares_init_options.3 - Sync ax_pthread.m4 with upstream - Sync ax_cxx_compile_stdcxx_11.m4 with upstream to fix uclibc support ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2317-1 Released: Tue May 30 14:01:22 2023 Summary: Recommended update for util-linux Type: recommended Severity: moderate References: 1210164 This update for util-linux fixes the following issue: - Add upstream patch to prevent possible performance degradation of libuuid (bsc#1210164) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2333-1 Released: Wed May 31 09:01:28 2023 Summary: Recommended update for zlib Type: recommended Severity: moderate References: 1210593 This update for zlib fixes the following issue: - Fix function calling order to avoid crashes (bsc#1210593) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2341-1 Released: Thu Jun 1 11:31:27 2023 Summary: Recommended update for libsigc++2 Type: recommended Severity: moderate References: 1209094,1209140 This update for libsigc++2 fixes the following issues: - Remove executable permission for file (bsc#1209094, bsc#1209140) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2342-1 Released: Thu Jun 1 11:34:20 2023 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1211430,CVE-2023-2650 This update for openssl-1_1 fixes the following issues: - CVE-2023-2650: Fixed possible denial of service translating ASN.1 object identifiers (bsc#1211430). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2347-1 Released: Thu Jun 1 14:33:10 2023 Summary: Security update for cups Type: security Severity: important References: 1211643,CVE-2023-32324 This update for cups fixes the following issues: - CVE-2023-32324: Fixed a buffer overflow in format_log_line() which could cause a denial-of-service (bsc#1211643). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2355-1 Released: Fri Jun 2 12:48:25 2023 Summary: Recommended update forlibrelp Type: recommended Severity: moderate References: 1210649 This update for librelp fixes the following issues: - update to librelp 1.11.0 (bsc#1210649) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2363-1 Released: Mon Jun 5 09:21:36 2023 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1209131,1209550,1209669,1209905,1210089,1210105 This update for libnvme, nvme-cli fixes the following issues: - Fix GC in Python binding (bsc#1209905 bsc#1209131) - Fix crash when printing json output for supported log pages (bsc#1209550) - Add coverity reported fixes (bsc#1209669) - Update host_traddr when using config.json file (bsc#1210089) - Fix compiler warning (git-fixes) - Fix condition in autoconnect service (bsc#1210105) - Set version-tag so that version are correctly reported ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2366-1 Released: Mon Jun 5 09:23:08 2023 Summary: Recommended update for xen Type: recommended Severity: moderate References: 1027519,1209237,1209245 This update for xen fixes the following issues: - Added debug-info to xen-syms (bsc#1209237) - Update to Xen 4.16.4 bug fix release (bsc#1027519) - Added upstream bug fixes (bsc#1027519) - Fix host-assisted kexec/kdump for HVM domUs (bsc#1209245) - Drop patches contained in new tarball and switch to upstream backports for some patches ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2430-1 Released: Tue Jun 6 22:55:28 2023 Summary: Recommended update for supportutils-plugin-suse-public-cloud Type: recommended Severity: critical References: This update for supportutils-plugin-suse-public-cloud fixes the following issues: - This update will be delivered to SLE Micro. (SMO-219) The following package changes have been done: - containerd-ctr-1.6.19-150000.90.3 updated -containerd-1.6.19-150000.90.3 updated - cups-config-2.2.7-150000.3.43.1 updated - curl-8.0.1-150400.5.23.1 updated - dracut-055+suse.342.g2e6dce8e-150400.3.22.1 updated - grub2-i386-pc-2.06-150400.11.33.1 updated - grub2-x86_64-efi-2.06-150400.11.33.1 updated - grub2-2.06-150400.11.33.1 updated - kbd-legacy-2.4.0-150400.5.6.1 updated - kbd-2.4.0-150400.5.6.1 updated - libblkid1-2.37.2-150400.8.17.1 updated - libcares2-1.19.1-150000.3.23.1 updated - libcups2-2.2.7-150000.3.43.1 updated - libcurl4-8.0.1-150400.5.23.1 updated - libfdisk1-2.37.2-150400.8.17.1 updated - libmount1-2.37.2-150400.8.17.1 updated - libnvme1-1.0+32.gb30ab4c96c2d-150400.3.21.1 updated - libopenssl1_1-1.1.1l-150400.7.37.1 updated - librelp0-1.11.0-150000.3.3.1 updated - libsigc-2_0-0-2.10.7-150400.3.3.1 updated - libsmartcols1-2.37.2-150400.8.17.1 updated - libsolv-tools-0.7.24-150400.3.6.4 updated - libsystemd0-249.16-150400.8.28.3 updated - libudev1-249.16-150400.8.28.3 updated - libuuid1-2.37.2-150400.8.17.1 updated - libz1-1.2.11-150000.3.45.1 updated - libzypp-17.31.11-150400.3.25.2 updated - nvme-cli-2.0+40.gd857ed9befd6-150400.3.18.1 updated - openssl-1_1-1.1.1l-150400.7.37.1 updated - python3-packaging-21.3-150200.3.3.1 updated - python3-setuptools-44.1.1-150400.9.3.3 updated - runc-1.1.5-150000.43.1 updated - supportutils-plugin-suse-public-cloud-1.0.7-150000.3.14.1 updated - systemd-sysvinit-249.16-150400.8.28.3 updated - systemd-249.16-150400.8.28.3 updated - udev-249.16-150400.8.28.3 updated - util-linux-systemd-2.37.2-150400.8.17.1 updated - util-linux-2.37.2-150400.8.17.1 updated - vim-data-common-9.0.1443-150000.5.43.1 updated - vim-9.0.1443-150000.5.43.1 updated - xen-libs-4.16.4_02-150400.4.28.1 updated - xxd-9.0.1443-150000.5.43.1 updated - zypper-1.14.60-150400.3.21.2 updated . SUSE has released an important security patch for sles-15-sp4-chost-byos-v20230606-arm64 that resolves several vulnerabilities associated with affected software components.. SLES 15 SP4, critical update, arm64 security issues, security patch, SUSEupdates. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.