Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 44 articles for you...
172

Ubuntu 22.04 LTS USN-7602-1: Important kernel vulnerabilities

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7602-1 June 26, 2025 linux-xilinx-zynqmp vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-xilinx-zynqmp: Linux kernel for Xilinx ZynqMP processors Details: Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbitrary code. (CVE-2024-8805) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly verify the target namespace when handling upcalls. An attacker could use this to expose sensitive information. (CVE-2025-2312) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - x86 architecture; - Block layer subsystem; - ACPI drivers; - Network block device driver; - Bus devices; - Character device driver; - TPM device driver; - Clock framework and drivers; - GPIO subsystem; - GPU drivers; - HID subsystem; - I2C subsystem; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - MemoryStick subsystem; - Network drivers; - Mellanox network drivers; - NTB driver; - PCI subsystem; - PPS (Pulse Per Second) driver; - PTP clock framework; - RapidIO drivers; - Voltage and Current Regulator drivers; - Remote Processor subsystem; - Real Time Clock drivers; - SCSI subsystem; - SLIMbusdrivers; - QCOM SoC drivers; - Trusted Execution Environment drivers; - Thermal drivers; - TTY drivers; - USB DSL drivers; - USB Device Class drivers; - USB core drivers; - USB Gadget drivers; - USB Host Controller drivers; - Renesas USBHS Controller drivers; - ACRN Hypervisor Service Module driver; - File systems infrastructure; - BTRFS file system; - Ext4 file system; - F2FS file system; - JFS file system; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - Overlay file system; - Proc file system; - SMB network file system; - UBI file system; - KVM subsystem; - IPv6 networking; - L3 Master device support module; - Netfilter; - RDMA verbs API; - SoC audio core drivers; - Process Accounting mechanism; - Padata parallel execution mechanism; - printk logging mechanism; - Scheduler infrastructure; - Timer subsystem; - Tracing infrastructure; - Watch queue notification mechanism; - Memory management; - 802.1Q VLAN protocol; - Asynchronous Transfer Mode (ATM) subsystem; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - Networking core; - IPv4 networking; - Logical Link layer; - Multipath TCP; - NFC subsystem; - Open vSwitch; - Rose network layer; - Network traffic control; - SMC sockets; - Sun RPC protocol; - Wireless networking; - Landlock security; - Linux Security Modules (LSM) Framework; - Tomoyo security module; - SoC Audio for Freescale CPUs drivers; (CVE-2025-21647, CVE-2025-21925, CVE-2024-58034, CVE-2024-46812, CVE-2024-56721, CVE-2025-21811, CVE-2025-21719, CVE-2025-21859, CVE-2025-21745, CVE-2023-53034, CVE-2025-21924, CVE-2024-58052, CVE-2024-58090, CVE-2025-21950, CVE-2025-21753, CVE-2024-57977, CVE-2025-21910, CVE-2025-21806, CVE-2024-58063, CVE-2025-21835, CVE-2024-58001, CVE-2025-21804, CVE-2025-21887,CVE-2024-53144, CVE-2025-38152, CVE-2024-56599, CVE-2025-22035, CVE-2025-22045, CVE-2025-21926, CVE-2024-58069, CVE-2025-21749, CVE-2023-52664, CVE-2025-21779, CVE-2025-21957, CVE-2025-21877, CVE-2025-22008, CVE-2025-21760, CVE-2025-22071, CVE-2025-22079, CVE-2024-56664, CVE-2024-42230, CVE-2025-21748, CVE-2025-21744, CVE-2025-21758, CVE-2025-21767, CVE-2025-21999, CVE-2025-21970, CVE-2025-21826, CVE-2025-38637, CVE-2025-21846, CVE-2025-22073, CVE-2025-23138, CVE-2025-22097, CVE-2025-22056, CVE-2024-58093, CVE-2025-21935, CVE-2025-21785, CVE-2025-22010, CVE-2025-22075, CVE-2025-21948, CVE-2025-21862, CVE-2025-38575, CVE-2025-22004, CVE-2025-22063, CVE-2025-21905, CVE-2025-21962, CVE-2025-21912, CVE-2025-21814, CVE-2024-58085, CVE-2025-22060, CVE-2025-21795, CVE-2024-46821, CVE-2025-21916, CVE-2024-46753, CVE-2022-49636, CVE-2025-22055, CVE-2025-21898, CVE-2025-21715, CVE-2024-58017, CVE-2025-21772, CVE-2025-21718, CVE-2024-36945, CVE-2025-21762, CVE-2025-22005, CVE-2025-21991, CVE-2024-58051, CVE-2025-21951, CVE-2025-21726, CVE-2024-58083, CVE-2025-21909, CVE-2025-21928, CVE-2025-21992, CVE-2024-58010, CVE-2025-39735, CVE-2025-21711, CVE-2025-21761, CVE-2025-21844, CVE-2024-58076, CVE-2024-58079, CVE-2025-21956, CVE-2025-21684, CVE-2025-21920, CVE-2025-21823, CVE-2025-21781, CVE-2025-21943, CVE-2025-37937, CVE-2025-21820, CVE-2023-52927, CVE-2024-57978, CVE-2025-21787, CVE-2025-21776, CVE-2025-21722, CVE-2025-21866, CVE-2025-22021, CVE-2025-21782, CVE-2025-22054, CVE-2024-58055, CVE-2025-21964, CVE-2025-21941, CVE-2024-57973, CVE-2025-22066, CVE-2025-21708, CVE-2025-21878, CVE-2025-21799, CVE-2025-22086, CVE-2025-21766, CVE-2025-37889, CVE-2024-58002, CVE-2025-21791, CVE-2025-21830, CVE-2025-21858, CVE-2025-22081, CVE-2024-57834, CVE-2024-58072, CVE-2024-57981, CVE-2025-21848, CVE-2025-21727, CVE-2025-21765, CVE-2024-58007, CVE-2025-21963, CVE-2024-56551, CVE-2022-49728, CVE-2025-21728, CVE-2024-58014, CVE-2025-21994, CVE-2025-21707, CVE-2025-21735, CVE-2025-23136, CVE-2025-21731,CVE-2024-58020, CVE-2025-21704, CVE-2024-57979, CVE-2025-21796, CVE-2025-21975, CVE-2025-22025, CVE-2024-56608, CVE-2025-21971, CVE-2025-21919, CVE-2025-22018, CVE-2024-26982, CVE-2024-47726, CVE-2025-21721, CVE-2025-22044, CVE-2025-21968, CVE-2025-21865, CVE-2025-21917, CVE-2025-21764, CVE-2024-58016, CVE-2025-21736, CVE-2024-57986, CVE-2025-21763, CVE-2024-58005, CVE-2025-21802, CVE-2025-21871, CVE-2025-37785, CVE-2025-21922, CVE-2025-21959, CVE-2025-22020, CVE-2024-58086, CVE-2025-22089, CVE-2025-22007, CVE-2025-39728, CVE-2025-22050, CVE-2025-21934, CVE-2025-21875, CVE-2025-21996, CVE-2025-21914, CVE-2024-58071, CVE-2024-58058, CVE-2024-57980, CVE-2025-21904, CVE-2025-21981, CVE-2024-53168, CVE-2025-22014) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1050-xilinx-zynqmp 5.15.0-1050.54 linux-image-xilinx-zynqmp 5.15.0.1050.53 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7602-1 CVE-2022-49636, CVE-2022-49728, CVE-2023-52664, CVE-2023-52927, CVE-2023-53034, CVE-2024-26982, CVE-2024-36945, CVE-2024-42230, CVE-2024-46753, CVE-2024-46812, CVE-2024-46821, CVE-2024-47726, CVE-2024-53144, CVE-2024-53168, CVE-2024-56551, CVE-2024-56599, CVE-2024-56608, CVE-2024-56664, CVE-2024-56721, CVE-2024-57834, CVE-2024-57973, CVE-2024-57977, CVE-2024-57978, CVE-2024-57979, CVE-2024-57980, CVE-2024-57981, CVE-2024-57986, CVE-2024-58001, CVE-2024-58002, CVE-2024-58005, CVE-2024-58007, CVE-2024-58010, CVE-2024-58014, CVE-2024-58016, CVE-2024-58017, CVE-2024-58020, CVE-2024-58034, CVE-2024-58051, CVE-2024-58052, CVE-2024-58055, CVE-2024-58058, CVE-2024-58063, CVE-2024-58069, CVE-2024-58071, CVE-2024-58072, CVE-2024-58076, CVE-2024-58079, CVE-2024-58083, CVE-2024-58085, CVE-2024-58086, CVE-2024-58090, CVE-2024-58093, CVE-2024-8805, CVE-2025-21647, CVE-2025-21684, CVE-2025-21704, CVE-2025-21707, CVE-2025-21708, CVE-2025-21711, CVE-2025-21715, CVE-2025-21718, CVE-2025-21719, CVE-2025-21721, CVE-2025-21722, CVE-2025-21726, CVE-2025-21727, CVE-2025-21728, CVE-2025-21731, CVE-2025-21735, CVE-2025-21736, CVE-2025-21744, CVE-2025-21745, CVE-2025-21748, CVE-2025-21749, CVE-2025-21753, CVE-2025-21758, CVE-2025-21760, CVE-2025-21761, CVE-2025-21762, CVE-2025-21763, CVE-2025-21764, CVE-2025-21765, CVE-2025-21766, CVE-2025-21767, CVE-2025-21772, CVE-2025-21776, CVE-2025-21779, CVE-2025-21781, CVE-2025-21782, CVE-2025-21785, CVE-2025-21787, CVE-2025-21791, CVE-2025-21795, CVE-2025-21796, CVE-2025-21799, CVE-2025-21802, CVE-2025-21804, CVE-2025-21806, CVE-2025-21811, CVE-2025-21814, CVE-2025-21820, CVE-2025-21823, CVE-2025-21826, CVE-2025-21830, CVE-2025-21835, CVE-2025-21844, CVE-2025-21846, CVE-2025-21848, CVE-2025-21858, CVE-2025-21859, CVE-2025-21862, CVE-2025-21865, CVE-2025-21866, CVE-2025-21871, CVE-2025-21875, CVE-2025-21877, CVE-2025-21878, CVE-2025-21887, CVE-2025-21898, CVE-2025-21904, CVE-2025-21905, CVE-2025-21909, CVE-2025-21910, CVE-2025-21912, CVE-2025-21914, CVE-2025-21916, CVE-2025-21917, CVE-2025-21919, CVE-2025-21920, CVE-2025-21922, CVE-2025-21924, CVE-2025-21925, CVE-2025-21926, CVE-2025-21928, CVE-2025-21934, CVE-2025-21935, CVE-2025-21941, CVE-2025-21943, CVE-2025-21948, CVE-2025-21950, CVE-2025-21951, CVE-2025-21956, CVE-2025-21957, CVE-2025-21959, CVE-2025-21962, CVE-2025-21963, CVE-2025-21964, CVE-2025-21968, CVE-2025-21970, CVE-2025-21971, CVE-2025-21975, CVE-2025-21981, CVE-2025-21991, CVE-2025-21992, CVE-2025-21994, CVE-2025-21996, CVE-2025-21999, CVE-2025-22004, CVE-2025-22005, CVE-2025-22007, CVE-2025-22008, CVE-2025-22010, CVE-2025-22014, CVE-2025-22018, CVE-2025-22020, CVE-2025-22021, CVE-2025-22025, CVE-2025-22035, CVE-2025-22044, CVE-2025-22045, CVE-2025-22050, CVE-2025-22054, CVE-2025-22055, CVE-2025-22056, CVE-2025-22060, CVE-2025-22063, CVE-2025-22066, CVE-2025-22071, CVE-2025-22073, CVE-2025-22075, CVE-2025-22079, CVE-2025-22081, CVE-2025-22086, CVE-2025-22089, CVE-2025-22097, CVE-2025-2312, CVE-2025-23136, CVE-2025-23138, CVE-2025-37785, CVE-2025-37889, CVE-2025-37937, CVE-2025-38152, CVE-2025-38575, CVE-2025-38637, CVE-2025-39728, CVE-2025-39735 Package Information: https://launchpad.net/ubuntu/+source/linux-xilinx-zynqmp/5.15.0-1050.54 . Important patch for Ubuntu 22.04 LTS resolving several kernel vulnerabilities, strengthening security and overall system robustness.. Linux Kernel Security, Ubuntu Update, Bluetooth Vulnerability, CIFS Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2025 Important Ubuntu
100

SUSE: 2025:20384-2 important: kernel-livepatch-MICRO-5-1-RT_Update_6

* bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References: . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_5 Announcement ID: SUSE-SU-2025:20383-1 Release Date: 2025-06-10T11:22:13Z Rating: moderate References: * bsc#1236701 * bsc#1239077 * bsc#1239096 Cross-References: * CVE-2024-57996 * CVE-2024-58013 * CVE-2025-21680 CVSS scores: * CVE-2024-57996 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-57996 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-58013 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2024-58013 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-58013 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21680 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-21680 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_5 fixes the following issues: * CVE-2025-21680: pktgen: avoid out-of-bounds access in get_imix_entries (bsc#1236701) * CVE-2024-58013: Bluetooth: MGMT: Fix slab-use-after-free Read in mgmt_remove_adv_monitor_sync (bsc#1239096) * CVE-2024-57996: net_sched: sch_sfq: don't allow 1 packet limit References: (bsc#1239077) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-34=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_5-debugsource-3-1.1 *kernel-livepatch-6_4_0-25-rt-3-1.1 * kernel-livepatch-6_4_0-25-rt-debuginfo-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-57996.html * https://www.suse.com/security/cve/CVE-2024-58013.html * https://www.suse.com/security/cve/CVE-2025-21680.html * https://bugzilla.suse.com/show_bug.cgi?id=1236701 * https://bugzilla.suse.com/show_bug.cgi?id=1239077 * https://bugzilla.suse.com/show_bug.cgi?id=1239096 . Notification for SUSE Linux Micro addresses significant concerns in kernel-livepatch related to multiple CVE findings. Immediate installation recommended.. Kernel Livepatch, SUSE Linux Update, Bluetooth Security Fix, Network Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 12, 2025 Important SuSE
172

Ubuntu 22.04 LTS USN-7500-2: Security Update for Azure Kernel

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7500-2 May 07, 2025 linux-azure-6.8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure-6.8: Linux kernel for Microsoft Azure cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Bluetooth drivers; - Microsoft Azure Network Adapter (MANA) driver; (CVE-2024-56653, CVE-2025-21953) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-6.8.0-1028-azure 6.8.0-1028.33~22.04.1 linux-image-6.8.0-1028-azure-fde 6.8.0-1028.33~22.04.1 linux-image-azure 6.8.0-1028.33~22.04.1 linux-image-azure-fde 6.8.0-1028.33~22.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7500-2 https://ubuntu.com/security/notices/USN-7500-1 CVE-2024-56653, CVE-2025-21953 Package Information: https://launchpad.net/ubuntu/+source/linux-azure-6.8/6.8.0-1028.33~22.04.1 . Multiple vulnerabilities in the Ubuntu 22.04 LTS Linux kernel have been addressed withcritical patches aimed specifically at Azure clients.. Linux Kernel Updates, Ubuntu Azure Security, Linux System Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2025 Important Ubuntu
172

Ubuntu 22.04 LTS USN-7179-4: Severe Bluetooth Issues Affecting Kernel

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7179-4 January 27, 2025 linux-xilinx-zynqmp vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-xilinx-zynqmp: Linux kernel for Xilinx ZynqMP processors Details: Andy Nguyen discovered that the Bluetooth L2CAP implementation in the Linux kernel contained a type-confusion error. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-12351) Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux kernel did not properly initialize memory in some situations. A physically proximate remote attacker could use this to expose sensitive information (kernel memory). (CVE-2020-12352) Andy Nguyen discovered that the Bluetooth HCI event packet parser in the Linux kernel did not properly handle event advertisements of certain sizes, leading to a heap-based buffer overflow. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-24490) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - GPU drivers; - Media drivers; - Network drivers; - SMB network file system; - Bluetooth subsystem; - Amateur Radio drivers; - Network traffic control; - VMware vSockets driver; (CVE-2024-43904, CVE-2024-35963, CVE-2024-35967, CVE-2024-40973, CVE-2024-26822, CVE-2024-35965, CVE-2024-40910, CVE-2024-38553, CVE-2024-53057, CVE-2024-50264, CVE-2024-35966) Updateinstructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1041-xilinx-zynqmp 5.15.0-1041.45 linux-image-xilinx-zynqmp 5.15.0.1041.45 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7179-4 https://ubuntu.com/security/notices/USN-7179-3 https://ubuntu.com/security/notices/USN-7179-2 https://ubuntu.com/security/notices/USN-7179-1 CVE-2020-12351, CVE-2020-12352, CVE-2020-24490, CVE-2024-26822, CVE-2024-35963, CVE-2024-35965, CVE-2024-35966, CVE-2024-35967, CVE-2024-38553, CVE-2024-40910, CVE-2024-40973, CVE-2024-43904, CVE-2024-50264, CVE-2024-53057 Package Information: https://launchpad.net/ubuntu/+source/linux-xilinx-zynqmp/5.15.0-1041.45 . Numerous security patches released for the Ubuntu linux-xilinx-zynqmp kernel tackling severe vulnerabilities. Stay informed to protect your device.. linux kernel vulnerabilities, Bluetooth security, Ubuntu patches. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 27, 2025 Critical Ubuntu
172

Ubuntu 22.04 LTS USN-7186-2 moderate: Kernel security updates

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7186-2 January 09, 2025 linux-azure, linux-intel-iotg-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-intel-iotg-5.15: Linux kernel for Intel IoT platforms Details: Andy Nguyen discovered that the Bluetooth L2CAP implementation in the Linux kernel contained a type-confusion error. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-12351) Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux kernel did not properly initialize memory in some situations. A physically proximate remote attacker could use this to expose sensitive information (kernel memory). (CVE-2020-12352) Andy Nguyen discovered that the Bluetooth HCI event packet parser in the Linux kernel did not properly handle event advertisements of certain sizes, leading to a heap-based buffer overflow. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-24490) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - ACPI drivers; - Drivers core; - ATA over ethernet (AOE) driver; - TPM device driver; - Clock framework and drivers; - Buffer Sharing and Synchronizationframework; - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - I2C subsystem; - InfiniBand drivers; - Input Device core drivers; - Mailbox framework; - Media drivers; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - STMicroelectronics network drivers; - NTB driver; - Virtio pmem driver; - PCI subsystem; - x86 platform drivers; - S/390 drivers; - SCSI subsystem; - SPI subsystem; - Thermal drivers; - USB Device Class drivers; - USB Type-C Port Controller Manager driver; - VFIO drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - 9P distributed file system; - BTRFS file system; - Ceph distributed file system; - File systems infrastructure; - Ext4 file system; - F2FS file system; - GFS2 file system; - JFS file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - SMB network file system; - Network file system (NFS) superblock; - Bluetooth subsystem; - Network traffic control; - Network sockets; - TCP network protocol; - BPF subsystem; - Perf events; - Kernel thread helper (kthread); - Padata parallel execution mechanism; - Arbitrary resource management; - Static call mechanism; - Tracing infrastructure; - Memory management; - Amateur Radio drivers; - Ethernet bridge; - CAN network layer; - Networking core; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - Netlink; - SCTP protocol; - TIPC protocol; - VMware vSockets driver; - SELinux security module; - Simplified Mandatory Access Control Kernel framework; - AudioScience HPI driver; - Amlogic Meson SoC drivers; - USB sound devices; (CVE-2024-47720, CVE-2023-52904, CVE-2024-49907,CVE-2024-50049, CVE-2024-38667, CVE-2024-47747, CVE-2024-50180, CVE-2024-47756, CVE-2024-50015, CVE-2024-49983, CVE-2024-49981, CVE-2024-38538, CVE-2024-47735, CVE-2024-50019, CVE-2024-49955, CVE-2024-38545, CVE-2024-49902, CVE-2024-46849, CVE-2024-49863, CVE-2024-49944, CVE-2024-50189, CVE-2024-49927, CVE-2024-50033, CVE-2024-50045, CVE-2024-49977, CVE-2024-35965, CVE-2024-42158, CVE-2024-49913, CVE-2024-50038, CVE-2024-49883, CVE-2024-38553, CVE-2024-49868, CVE-2024-50264, CVE-2024-46855, CVE-2024-50188, CVE-2024-49952, CVE-2024-47718, CVE-2024-50095, CVE-2024-49936, CVE-2024-47734, CVE-2024-47713, CVE-2024-47723, CVE-2024-49886, CVE-2024-50044, CVE-2024-49985, CVE-2024-49973, CVE-2024-49895, CVE-2024-47693, CVE-2024-46858, CVE-2024-50003, CVE-2024-39463, CVE-2024-46852, CVE-2024-49867, CVE-2024-49967, CVE-2024-47706, CVE-2024-35904, CVE-2024-47698, CVE-2024-47701, CVE-2024-36893, CVE-2024-50031, CVE-2024-47699, CVE-2024-47674, CVE-2024-49871, CVE-2024-42156, CVE-2024-50179, CVE-2024-49995, CVE-2024-49938, CVE-2024-47692, CVE-2024-49975, CVE-2024-47710, CVE-2024-49860, CVE-2024-36968, CVE-2024-53057, CVE-2024-50186, CVE-2024-47695, CVE-2024-40973, CVE-2024-35966, CVE-2024-46865, CVE-2024-47697, CVE-2024-47757, CVE-2023-52639, CVE-2024-47709, CVE-2024-47672, CVE-2024-50040, CVE-2024-49890, CVE-2024-49933, CVE-2024-38544, CVE-2024-49858, CVE-2024-42079, CVE-2024-46853, CVE-2024-50006, CVE-2024-47670, CVE-2024-49896, CVE-2024-50013, CVE-2024-49924, CVE-2024-50093, CVE-2024-49884, CVE-2024-49935, CVE-2024-50184, CVE-2024-27072, CVE-2024-46695, CVE-2024-49997, CVE-2024-49903, CVE-2024-50001, CVE-2024-49969, CVE-2024-49851, CVE-2024-44940, CVE-2024-46859, CVE-2024-44942, CVE-2024-49958, CVE-2024-49930, CVE-2024-49949, CVE-2024-49881, CVE-2024-47690, CVE-2024-49882, CVE-2024-49875, CVE-2024-49959, CVE-2024-46854, CVE-2024-35963, CVE-2024-40910, CVE-2024-49965, CVE-2024-50035, CVE-2024-49957, CVE-2024-50059, CVE-2024-49894, CVE-2024-47685, CVE-2024-50181, CVE-2024-50024, CVE-2024-50062,CVE-2024-43904, CVE-2024-49946, CVE-2024-41016, CVE-2023-52621, CVE-2024-26822, CVE-2024-49877, CVE-2024-35967, CVE-2024-47742, CVE-2024-47739, CVE-2024-26947, CVE-2024-47748, CVE-2024-47737, CVE-2024-44931, CVE-2024-49900, CVE-2024-50041, CVE-2024-50046, CVE-2024-50002, CVE-2024-49852, CVE-2024-50039, CVE-2024-47679, CVE-2024-47749, CVE-2024-49982, CVE-2024-49878, CVE-2024-47712, CVE-2024-47740, CVE-2024-49962, CVE-2024-50096, CVE-2024-49948, CVE-2024-50000, CVE-2024-47671, CVE-2024-49892, CVE-2024-47673, CVE-2024-35951, CVE-2023-52917, CVE-2024-49889, CVE-2024-49954, CVE-2024-38632, CVE-2024-47696, CVE-2024-50007, CVE-2024-47705, CVE-2024-50008, CVE-2024-49966, CVE-2024-49856, CVE-2023-52532, CVE-2024-49866, CVE-2024-47684, CVE-2024-49963, CVE-2024-50191, CVE-2024-49879) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1078-azure 5.15.0-1078.87 linux-image-azure-lts-22.04 5.15.0.1078.76 Ubuntu 20.04 LTS linux-image-5.15.0-1071-intel-iotg 5.15.0-1071.77~20.04.1 linux-image-intel 5.15.0.1071.77~20.04.1 linux-image-intel-iotg 5.15.0.1071.77~20.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7186-2 https://ubuntu.com/security/notices/USN-7186-1 CVE-2020-12351, CVE-2020-12352, CVE-2020-24490, CVE-2023-52532, CVE-2023-52621, CVE-2023-52639, CVE-2023-52904, CVE-2023-52917, CVE-2024-26822,CVE-2024-26947, CVE-2024-27072, CVE-2024-35904, CVE-2024-35951, CVE-2024-35963, CVE-2024-35965, CVE-2024-35966, CVE-2024-35967, CVE-2024-36893, CVE-2024-36968, CVE-2024-38538, CVE-2024-38544, CVE-2024-38545, CVE-2024-38553, CVE-2024-38632, CVE-2024-38667, CVE-2024-39463, CVE-2024-40910, CVE-2024-40973, CVE-2024-41016, CVE-2024-42079, CVE-2024-42156, CVE-2024-42158, CVE-2024-43904, CVE-2024-44931, CVE-2024-44940, CVE-2024-44942, CVE-2024-46695, CVE-2024-46849, CVE-2024-46852, CVE-2024-46853, CVE-2024-46854, CVE-2024-46855, CVE-2024-46858, CVE-2024-46859, CVE-2024-46865, CVE-2024-47670, CVE-2024-47671, CVE-2024-47672, CVE-2024-47673, CVE-2024-47674, CVE-2024-47679, CVE-2024-47684, CVE-2024-47685, CVE-2024-47690, CVE-2024-47692, CVE-2024-47693, CVE-2024-47695, CVE-2024-47696, CVE-2024-47697, CVE-2024-47698, CVE-2024-47699, CVE-2024-47701, CVE-2024-47705, CVE-2024-47706, CVE-2024-47709, CVE-2024-47710, CVE-2024-47712, CVE-2024-47713, CVE-2024-47718, CVE-2024-47720, CVE-2024-47723, CVE-2024-47734, CVE-2024-47735, CVE-2024-47737, CVE-2024-47739, CVE-2024-47740, CVE-2024-47742, CVE-2024-47747, CVE-2024-47748, CVE-2024-47749, CVE-2024-47756, CVE-2024-47757, CVE-2024-49851, CVE-2024-49852, CVE-2024-49856, CVE-2024-49858, CVE-2024-49860, CVE-2024-49863, CVE-2024-49866, CVE-2024-49867, CVE-2024-49868, CVE-2024-49871, CVE-2024-49875, CVE-2024-49877, CVE-2024-49878, CVE-2024-49879, CVE-2024-49881, CVE-2024-49882, CVE-2024-49883, CVE-2024-49884, CVE-2024-49886, CVE-2024-49889, CVE-2024-49890, CVE-2024-49892, CVE-2024-49894, CVE-2024-49895, CVE-2024-49896, CVE-2024-49900, CVE-2024-49902, CVE-2024-49903, CVE-2024-49907, CVE-2024-49913, CVE-2024-49924, CVE-2024-49927, CVE-2024-49930, CVE-2024-49933, CVE-2024-49935, CVE-2024-49936, CVE-2024-49938, CVE-2024-49944, CVE-2024-49946, CVE-2024-49948, CVE-2024-49949, CVE-2024-49952, CVE-2024-49954, CVE-2024-49955, CVE-2024-49957, CVE-2024-49958, CVE-2024-49959,CVE-2024-49962, CVE-2024-49963, CVE-2024-49965, CVE-2024-49966, CVE-2024-49967, CVE-2024-49969, CVE-2024-49973, CVE-2024-49975, CVE-2024-49977, CVE-2024-49981, CVE-2024-49982, CVE-2024-49983, CVE-2024-49985, CVE-2024-49995, CVE-2024-49997, CVE-2024-50000, CVE-2024-50001, CVE-2024-50002, CVE-2024-50003, CVE-2024-50006, CVE-2024-50007, CVE-2024-50008, CVE-2024-50013, CVE-2024-50015, CVE-2024-50019, CVE-2024-50024, CVE-2024-50031, CVE-2024-50033, CVE-2024-50035, CVE-2024-50038, CVE-2024-50039, CVE-2024-50040, CVE-2024-50041, CVE-2024-50044, CVE-2024-50045, CVE-2024-50046, CVE-2024-50049, CVE-2024-50059, CVE-2024-50062, CVE-2024-50093, CVE-2024-50095, CVE-2024-50096, CVE-2024-50179, CVE-2024-50180, CVE-2024-50181, CVE-2024-50184, CVE-2024-50186, CVE-2024-50188, CVE-2024-50189, CVE-2024-50191, CVE-2024-50264, CVE-2024-53057 Package Information: https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1078.87 https://launchpad.net/ubuntu/+source/linux-intel-iotg-5.15/5.15.0-1071.77~20.04.1 . Debian Linux kernel patches address multiple vulnerabilities, highlighting significant risks associated with Bluetooth functionality across diverse platforms.. Linux kernel updates, Ubuntu security, Bluetooth vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jan 09, 2025 Ubuntu
89

Fedora 41: Critical Firmware Updates for Intel and Bluetooth Devices

Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-516b214c25 2024-12-13 01:33:43.480316+00:00 -------------------------------------------------------------------------------- Name : linux-firmware Product : Fedora 41 Version : 20241210 Release : 1.fc41 URL : http://www.kernel.org/ Summary : Firmware files used by the Linux kernel Description : This package includes firmware files required for some devices to operate. -------------------------------------------------------------------------------- Update Information: Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x i915: Update Xe2LPD DMC to v2.24 cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops iwlwifi: add Bz-gf FW for core89-91 release QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2 ice: update ice DDP wireless_edge package to 1.3.20.0 ice: update ice DDP comms package to 1.3.52.0 ice: update ice DDP package to ice-1.3.41.0 amdgpu: update DMCUB to v9.0.10.0 for DCN314/DCN351 Update AMD cpu microcode xe: Update GUC to v70.36.0 for BMG, LNL i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL iwlwifi: add Bz-gf FW for core91-69 release qcom: venus-5.4: add venus firmware file for qcs615 qcom: update venus firmware file for SC7280 QCA: Add 22 bluetooth firmware nvm files for QCA2066 mediatek MT7921/MT7922: update bluetooth firmware update for MT7921/MT7922 WiFi device qcom: Add QDU100 firmware image files. qcom: Update aic100 firmware files -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 10 2024 Peter Robinson - 20241210-1 -Update to upstream 20241210 - Update firmware file for Intel BlazarU core - amdgpu: numerous firmware updates - upstream amdnpu firmware - QCA: Add Bluetooth nvm files for WCN785x - i915: Update Xe2LPD DMC to v2.24 - cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops - iwlwifi: add Bz-gf FW for core89-91 release - QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2 - ice: update ice DDP wireless_edge package to 1.3.20.0 - ice: update ice DDP comms package to 1.3.52.0 - ice: update ice DDP package to ice-1.3.41.0 - amdgpu: update DMCUB to v9.0.10.0 for DCN314/DCN351 - Update AMD cpu microcode - xe: Update GUC to v70.36.0 for BMG, LNL - i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL - iwlwifi: add Bz-gf FW for core91-69 release - qcom: venus-5.4: add venus firmware file for qcs615 - qcom: update venus firmware file for SC7280 - QCA: Add 22 bluetooth firmware nvm files for QCA2066 - mediatek MT7921/MT7922: update bluetooth firmware - update for MT7921/MT7922 WiFi device - qcom: Add QDU100 firmware image files. - qcom: Update aic100 firmware files -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-516b214c25' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 41 firmware enhancements bolster security and efficiency for Intel and Bluetooth equipment featuring essential upgrades.. Firmware Updates, Fedora, Security Advisory, Intel, AMDGPU. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 13, 2024 Critical Fedora
100

SUSE Linux 15 SP6: 2024:3834-1 important: Kernel RT Live Patch security

* bsc#1225011 * bsc#1225012 * bsc#1225309 * bsc#1225311 * bsc#1225819 . # Security update for the Linux Kernel RT (Live Patch 0 for SLE 15 SP6) Announcement ID: SUSE-SU-2024:3834-1 Release Date: 2024-10-30T18:34:25Z Rating: important References: * bsc#1225011 * bsc#1225012 * bsc#1225309 * bsc#1225311 * bsc#1225819 * bsc#1226327 * bsc#1231419 Cross-References: * CVE-2023-52752 * CVE-2024-35862 * CVE-2024-35863 * CVE-2024-35864 * CVE-2024-35867 * CVE-2024-35905 * CVE-2024-42133 CVSS scores: * CVE-2023-52752 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52752 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35862 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35863 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35864 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35867 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35905 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-42133 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-42133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_8 fixes several issues. The following security issues were fixed: * CVE-2024-35905: Fixed int overflow for stack access size (bsc#1226327). * CVE-2024-42133: Bluetooth: Ignore too large handle values in BIG (bsc#1231419) * CVE-2024-35863: Fixed potential UAF in is_valid_oplock_break() (bsc#1225011). * CVE-2023-52752: smb: client: fix use-after-free bug in cifs_debug_data_proc_show()(bsc#1225819). * CVE-2024-35862: Fixed potential UAF in smb2_is_network_name_deleted() (bsc#1225311). * CVE-2024-35867: Fixed potential UAF in cifs_stats_proc_show() (bsc#1225012). * CVE-2024-35864: Fixed potential UAF in smb2_is_valid_lease_break() (bsc#1225309). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2024-3834=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (x86_64) * kernel-livepatch-6_4_0-150600_8-rt-5-150600.3.1 * kernel-livepatch-SLE15-SP6-RT_Update_0-debugsource-5-150600.3.1 * kernel-livepatch-6_4_0-150600_8-rt-debuginfo-5-150600.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-52752.html * https://www.suse.com/security/cve/CVE-2024-35862.html * https://www.suse.com/security/cve/CVE-2024-35863.html * https://www.suse.com/security/cve/CVE-2024-35864.html * https://www.suse.com/security/cve/CVE-2024-35867.html * https://www.suse.com/security/cve/CVE-2024-35905.html * https://www.suse.com/security/cve/CVE-2024-42133.html * https://bugzilla.suse.com/show_bug.cgi?id=1225011 * https://bugzilla.suse.com/show_bug.cgi?id=1225012 * https://bugzilla.suse.com/show_bug.cgi?id=1225309 * https://bugzilla.suse.com/show_bug.cgi?id=1225311 * https://bugzilla.suse.com/show_bug.cgi?id=1225819 * https://bugzilla.suse.com/show_bug.cgi?id=1226327 * https://bugzilla.suse.com/show_bug.cgi?id=1231419 . Crucial update addresses various vulnerabilities in SUSE Linux Kernel RT for SLE 15 SP6, strengthening overall system security.. SUSE Security Advisory, Kernel Security Update, Live Patching SUSE, Real Time Security, Bluetooth Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 30, 2024 Important SuSE
172

Ubuntu 18.04 LTS: USN-6973-4 Moderate: Bluetooth System Crash

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6973-4 September 02, 2024 linux-raspi-5.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-raspi-5.4: Linux kernel for Raspberry Pi systems Details: It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel, leading to a null pointer dereference vulnerability. A privileged local attacker could use this to possibly cause a denial of service (system crash). (CVE-2024-24860) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SuperH RISC architecture; - MMC subsystem; - Network drivers; - SCSI drivers; - GFS2 file system; - IPv4 networking; - IPv6 networking; - HD-audio driver; (CVE-2024-26830, CVE-2024-39484, CVE-2024-36901, CVE-2024-26929, CVE-2024-26921, CVE-2021-46926, CVE-2023-52629, CVE-2023-52760) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS linux-image-5.4.0-1115-raspi 5.4.0-1115.127~18.04.1 Available with Ubuntu Pro linux-image-raspi-hwe-18.04 5.4.0.1115.127~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manuallyuninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6973-4 https://ubuntu.com/security/notices/USN-6973-3 https://ubuntu.com/security/notices/USN-6973-2 https://ubuntu.com/security/notices/USN-6973-1 CVE-2021-46926, CVE-2023-52629, CVE-2023-52760, CVE-2024-24860, CVE-2024-26830, CVE-2024-26921, CVE-2024-26929, CVE-2024-36901, CVE-2024-39484 . Resolutions for Linux kernel vulnerabilities boost Raspberry Pi safety. Ensure your devices are updated for vital defenses against threats.. Ubuntu Kernel Update, Raspberry Pi Security, Linux Kernel Issues, System Compromise, Bluetooth Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2024 Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200