Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7495-1 May 06, 2025 linux, linux-aws, linux-aws-5.4, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-kvm, linux-oracle, linux-oracle-5.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems - linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.4: Linux hardware enablement (HWE) kernel - linux-oracle-5.4: Linux kernel for Oracle Cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Ceph distributed file system; - Netfilter; (CVE-2023-52927, CVE-2023-52664, CVE-2024-26689) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1091-ibm 5.4.0-1091.96 linux-image-5.4.0-1132-kvm 5.4.0-1132.141 linux-image-5.4.0-1143-oracle 5.4.0-1143.153 linux-image-5.4.0-1145-aws 5.4.0-1145.155 linux-image-5.4.0-1148-gcp 5.4.0-1148.157 linux-image-5.4.0-215-generic 5.4.0-215.235 linux-image-5.4.0-215-generic-lpae 5.4.0-215.235 linux-image-5.4.0-215-lowlatency 5.4.0-215.235 linux-image-aws-lts-20.04 5.4.0.1145.142 linux-image-gcp-lts-20.04 5.4.0.1148.150 linux-image-generic 5.4.0.215.208 linux-image-generic-lpae 5.4.0.215.208 linux-image-ibm-lts-20.04 5.4.0.1091.120 linux-image-kvm 5.4.0.1132.128 linux-image-lowlatency 5.4.0.215.208 linux-image-oem 5.4.0.215.208 linux-image-oem-osp1 5.4.0.215.208 linux-image-oracle-lts-20.04 5.4.0.1143.137 linux-image-virtual 5.4.0.215.208 Ubuntu 18.04 LTS linux-image-5.4.0-1143-oracle 5.4.0-1143.153~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1145-aws 5.4.0-1145.155~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1148-gcp 5.4.0-1148.157~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1150-azure 5.4.0-1150.157~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-215-generic 5.4.0-215.235~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-215-lowlatency 5.4.0-215.235~18.04.1 Available with Ubuntu Pro linux-image-aws 5.4.0.1145.155~18.04.1 Available with Ubuntu Pro linux-image-azure 5.4.0.1150.157~18.04.1 Available with Ubuntu Pro linux-image-gcp 5.4.0.1148.157~18.04.1 Available with Ubuntu Pro linux-image-generic-hwe-18.04 5.4.0.215.235~18.04.1 Available with Ubuntu Pro linux-image-lowlatency-hwe-18.04 5.4.0.215.235~18.04.1 Available with Ubuntu Pro linux-image-oem 5.4.0.215.235~18.04.1 Available with Ubuntu Pro linux-image-oem-osp1 5.4.0.215.235~18.04.1 Available with Ubuntu Pro linux-image-oracle 5.4.0.1143.153~18.04.1 Available with Ubuntu Pro linux-image-snapdragon-hwe-18.04 5.4.0.215.235~18.04.1 Available with Ubuntu Pro linux-image-virtual-hwe-18.04 5.4.0.215.235~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7495-1 CVE-2023-52664, CVE-2023-52927, CVE-2024-26689 Package Information: https://launchpad.net/ubuntu/+source/linux/5.4.0-215.235 https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1145.155 https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1148.157 https://launchpad.net/ubuntu/+source/linux-ibm/5.4.0-1091.96 https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1132.141 https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1143.153 . Uncover essential security patches for Ubuntu 20.04 and 18.04 LTS kernel versions. Timely updates are necessary to ensure system protection.. Ubuntu Kernel Update, Linux Security Fixes, AWS GCP Kernel Security, Cloud Systems Vulnerabilities. . LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6701-1 March 18, 2024 linux, linux-aws, linux-hwe, linux-kvm, linux-oracle vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-hwe: Linux hardware enablement (HWE) kernel Details: Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did not properly perform permissions checks when handling HCI sockets. A physically proximate attacker could use this to cause a denial of service (bluetooth communication). (CVE-2023-2002) It was discovered that the NVIDIA Tegra XUSB pad controller driver in the Linux kernel did not properly handle return values in certain error conditions. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-23000) It was discovered that Spectre-BHB mitigations were missing for Ampere processors. A local attacker could potentially use this to expose sensitive information. (CVE-2023-3006) It was discovered that the ext4 file system implementation in the Linux kernel did not properly handle block device modification while it is mounted. A privileged attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-34256) Eric Dumazet discovered that the netfilter subsystem in the Linux kernel did not properly handle DCCP conntrack buffers in certain situations, leading to an out-of-bounds readvulnerability. An attacker could possibly use this to expose sensitive information (kernel memory). (CVE-2023-39197) It was discovered that the Siano USB MDTV receiver device driver in the Linux kernel did not properly handle device initialization failures in certain situations, leading to a use-after-free vulnerability. A physically proximate attacker could use this cause a denial of service (system crash). (CVE-2023-4132) Pratyush Yadav discovered that the Xen network backend implementation in the Linux kernel did not properly handle zero length data request, leading to a null pointer dereference vulnerability. An attacker in a guest VM could possibly use this to cause a denial of service (host domain crash). (CVE-2023-46838) It was discovered that a race condition existed in the AppleTalk networking subsystem of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-51781) Alon Zahavi discovered that the NVMe-oF/TCP subsystem of the Linux kernel did not properly handle connect command payloads in certain situations, leading to an out-of-bounds read vulnerability. A remote attacker could use this to expose sensitive information (kernel memory). (CVE-2023-6121) It was discovered that the ext4 file system implementation in the Linux kernel did not properly handle the remount operation in certain cases, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2024-0775) Notselwyn discovered that the netfilter subsystem in the Linux kernel did not properly handle verdict parameters in certain cases, leading to a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2024-1086) It was discovered that a race condition existed in the SCSIEmulex LightPulse Fibre Channel driver in the Linux kernel when unregistering FCF and re-scanning an HBA FCF table, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2024-24855) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS (Available with Ubuntu Pro): linux-image-4.15.0-1129-oracle 4.15.0-1129.140 linux-image-4.15.0-1150-kvm 4.15.0-1150.155 linux-image-4.15.0-1166-aws 4.15.0-1166.179 linux-image-4.15.0-223-generic 4.15.0-223.235 linux-image-4.15.0-223-lowlatency 4.15.0-223.235 linux-image-aws-lts-18.04 4.15.0.1166.164 linux-image-generic 4.15.0.223.207 linux-image-kvm 4.15.0.1150.141 linux-image-lowlatency 4.15.0.223.207 linux-image-oracle-lts-18.04 4.15.0.1129.134 linux-image-virtual 4.15.0.223.207 Ubuntu 16.04 LTS (Available with Ubuntu Pro): linux-image-4.15.0-223-generic 4.15.0-223.235~16.04.1 linux-image-4.15.0-223-lowlatency 4.15.0-223.235~16.04.1 linux-image-generic-hwe-16.04 4.15.0.223.7 linux-image-lowlatency-hwe-16.04 4.15.0.223.7 linux-image-oem 4.15.0.223.7 linux-image-virtual-hwe-16.04 4.15.0.223.7 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6701-1 CVE-2023-2002, CVE-2023-23000, CVE-2023-3006, CVE-2023-34256, CVE-2023-39197, CVE-2023-4132, CVE-2023-46838, CVE-2023-51781, CVE-2023-6121, CVE-2024-0775, CVE-2024-1086, CVE-2024-24855 . Debian Security Alert DSA-1234-1 identifies multiple vulnerabilities in the Python package and recommends immediate upgrades.. Kernel Security, Ubuntu 18.04, AWS Systems, System Update. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-6193-1 June 29, 2023 linux, linux-aws, linux-aws-5.15, linux-aws-5.4, linux-azure, linux-azure-5.15, linux-azure-5.4, linux-azure-fde-5.15, linux-bluefield, linux-gcp, linux-gcp-5.15, linux-gcp-5.4, linux-gke, linux-gke-5.15, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-kvm: Linux kernel for cloud environments - linux-lowlatency: Linux low latency kernel - linux-raspi: Linux kernel for Raspberry Pi systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-nvidia: Linux kernel for NVIDIA systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-aws-5.15: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-5.15: Linux kernel for Microsoft Azure cloud systems - linux-azure-fde-5.15: Linux kernel for Microsoft Azure CVM cloud systems - linux-bluefield: Linux kernel for NVIDIA BlueField platforms - linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke-5.15: Linux kernel forGoogle Container Engine (GKE) systems - linux-gkeop-5.15: Linux kernel for Google Container Engine (GKE) systems - linux-hwe-5.15: Linux hardware enablement (HWE) kernel - linux-lowlatency-hwe-5.15: Linux low latency kernel - linux-oracle-5.15: Linux kernel for Oracle Cloud systems - linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems - linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.4: Linux hardware enablement (HWE) kernel - linux-ibm-5.4: Linux kernel for IBM cloud systems - linux-oracle-5.4: Linux kernel for Oracle Cloud systems - linux-raspi-5.4: Linux kernel for Raspberry Pi systems Details: Hangyu Hua discovered that the Flower classifier implementation in the Linux kernel contained an out-of-bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-35788, LP: #2023577) It was discovered that for some Intel processors the INVLPG instruction implementation did not properly flush global TLB entries when PCIDs are enabled. An attacker could use this to expose sensitive information (kernel memory) or possibly cause undesired behaviors. (LP: #2023220) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: linux-image-6.2.0-1006-aws 6.2.0-1006.6 linux-image-6.2.0-1007-kvm 6.2.0-1007.7 linux-image-6.2.0-1007-lowlatency 6.2.0-1007.7 linux-image-6.2.0-1007-lowlatency-64k 6.2.0-1007.7 linux-image-6.2.0-1007-raspi 6.2.0-1007.9 linux-image-6.2.0-1007-raspi-nolpae 6.2.0-1007.9 linux-image-6.2.0-24-generic 6.2.0-24.24 linux-image-6.2.0-24-generic-64k 6.2.0-24.24 linux-image-6.2.0-24-generic-lpae 6.2.0-24.24 linux-image-aws 6.2.0.1006.7 linux-image-generic 6.2.0.24.24 linux-image-generic-64k 6.2.0.24.24 linux-image-generic-lpae 6.2.0.24.24 linux-image-kvm 6.2.0.1007.7 linux-image-lowlatency 6.2.0.1007.7 linux-image-lowlatency-64k 6.2.0.1007.7 linux-image-raspi 6.2.0.1007.10 linux-image-raspi-nolpae 6.2.0.1007.10 linux-image-virtual 6.2.0.24.24 Ubuntu 22.04 LTS: linux-image-5.15.0-1023-gkeop 5.15.0-1023.28 linux-image-5.15.0-1028-nvidia 5.15.0-1028.28 linux-image-5.15.0-1028-nvidia-lowlatency 5.15.0-1028.28 linux-image-5.15.0-1033-ibm 5.15.0-1033.36 linux-image-5.15.0-1033-raspi 5.15.0-1033.36 linux-image-5.15.0-1033-raspi-nolpae 5.15.0-1033.36 linux-image-5.15.0-1037-gcp 5.15.0-1037.45 linux-image-5.15.0-1037-gke 5.15.0-1037.42 linux-image-5.15.0-1037-kvm 5.15.0-1037.42 linux-image-5.15.0-1038-oracle 5.15.0-1038.44 linux-image-5.15.0-1039-aws 5.15.0-1039.44 linux-image-5.15.0-1041-azure 5.15.0-1041.48 linux-image-5.15.0-76-generic 5.15.0-76.83 linux-image-5.15.0-76-generic-64k 5.15.0-76.83 linux-image-5.15.0-76-generic-lpae 5.15.0-76.83 linux-image-5.15.0-76-lowlatency 5.15.0-76.83 linux-image-5.15.0-76-lowlatency-64k 5.15.0-76.83 linux-image-aws-lts-22.04 5.15.0.1039.38 linux-image-azure 5.15.0.1041.37 linux-image-azure-lts-22.04 5.15.0.1041.37 linux-image-gcp-lts-22.04 5.15.0.1037.33 linux-image-generic 5.15.0.76.74 linux-image-generic-64k 5.15.0.76.74 linux-image-generic-lpae 5.15.0.76.74 linux-image-gke 5.15.0.1037.36 linux-image-gke-5.15 5.15.0.1037.36 linux-image-gkeop 5.15.0.1023.22 linux-image-gkeop-5.15 5.15.0.1023.22 linux-image-ibm 5.15.0.1033.29 linux-image-kvm 5.15.0.1037.33 linux-image-lowlatency 5.15.0.76.81 linux-image-lowlatency-64k 5.15.0.76.81 linux-image-nvidia 5.15.0.1028.28 linux-image-nvidia-lowlatency 5.15.0.1028.28 linux-image-oracle 5.15.0.1038.33 linux-image-raspi 5.15.0.1033.30 linux-image-raspi-nolpae 5.15.0.1033.30 linux-image-virtual 5.15.0.76.74 Ubuntu 20.04 LTS: linux-image-5.15.0-1023-gkeop 5.15.0-1023.28~20.04.1 linux-image-5.15.0-1037-gcp 5.15.0-1037.45~20.04.1 linux-image-5.15.0-1037-gke 5.15.0-1037.42~20.04.1 linux-image-5.15.0-1038-oracle 5.15.0-1038.44~20.04.1 linux-image-5.15.0-1039-aws 5.15.0-1039.44~20.04.1 linux-image-5.15.0-1041-azure 5.15.0-1041.48~20.04.1 linux-image-5.15.0-1041-azure-fde 5.15.0-1041.48~20.04.1.1 linux-image-5.15.0-76-generic 5.15.0-76.83~20.04.1 linux-image-5.15.0-76-generic-64k 5.15.0-76.83~20.04.1 linux-image-5.15.0-76-generic-lpae 5.15.0-76.83~20.04.1 linux-image-5.15.0-76-lowlatency 5.15.0-76.83~20.04.1 linux-image-5.15.0-76-lowlatency-64k 5.15.0-76.83~20.04.1 linux-image-5.4.0-1052-ibm 5.4.0-1052.57 linux-image-5.4.0-1066-bluefield 5.4.0-1066.72 linux-image-5.4.0-1072-gkeop 5.4.0-1072.76 linux-image-5.4.0-1089-raspi 5.4.0-1089.100 linux-image-5.4.0-1094-kvm 5.4.0-1094.100 linux-image-5.4.0-1104-oracle 5.4.0-1104.113 linux-image-5.4.0-1105-aws 5.4.0-1105.113 linux-image-5.4.0-1108-gcp 5.4.0-1108.117 linux-image-5.4.0-1111-azure 5.4.0-1111.117 linux-image-5.4.0-153-generic 5.4.0-153.170 linux-image-5.4.0-153-generic-lpae 5.4.0-153.170 linux-image-5.4.0-153-lowlatency 5.4.0-153.170 linux-image-aws 5.15.0.1039.44~20.04.28 linux-image-aws-lts-20.04 5.4.0.1105.102 linux-image-azure 5.15.0.1041.48~20.04.31 linux-image-azure-cvm 5.15.0.1041.48~20.04.31 linux-image-azure-fde 5.15.0.1041.48~20.04.1.20 linux-image-azure-lts-20.04 5.4.0.1111.104 linux-image-bluefield 5.4.0.1066.61 linux-image-gcp 5.15.0.1037.45~20.04.1 linux-image-gcp-lts-20.04 5.4.0.1108.110 linux-image-generic 5.4.0.153.150 linux-image-generic-64k-hwe-20.04 5.15.0.76.83~20.04.37 linux-image-generic-hwe-20.04 5.15.0.76.83~20.04.37 linux-image-generic-lpae 5.4.0.153.150 linux-image-generic-lpae-hwe-20.04 5.15.0.76.83~20.04.37 linux-image-gke-5.15 5.15.0.1037.42~20.04.1 linux-image-gkeop 5.4.0.1072.70 linux-image-gkeop-5.15 5.15.0.1023.28~20.04.19 linux-image-gkeop-5.4 5.4.0.1072.70 linux-image-ibm 5.4.0.1052.78 linux-image-ibm-lts-20.04 5.4.0.1052.78 linux-image-kvm 5.4.0.1094.89 linux-image-lowlatency 5.4.0.153.150 linux-image-lowlatency-64k-hwe-20.04 5.15.0.76.83~20.04.34 linux-image-lowlatency-hwe-20.04 5.15.0.76.83~20.04.34 linux-image-oem 5.4.0.153.150 linux-image-oem-20.04 5.15.0.76.83~20.04.37 linux-image-oem-20.04b 5.15.0.76.83~20.04.37 linux-image-oem-20.04c 5.15.0.76.83~20.04.37 linux-image-oem-20.04d 5.15.0.76.83~20.04.37 linux-image-oem-osp1 5.4.0.153.150 linux-image-oracle 5.15.0.1038.44~20.04.1 linux-image-oracle-lts-20.04 5.4.0.1104.97 linux-image-raspi 5.4.0.1089.119 linux-image-raspi-hwe-18.04 5.4.0.1089.119 linux-image-raspi2 5.4.0.1089.119 linux-image-raspi2-hwe-18.04 5.4.0.1089.119 linux-image-virtual 5.4.0.153.150 linux-image-virtual-hwe-20.04 5.15.0.76.83~20.04.37 Ubuntu 18.04 LTS (Available with Ubuntu Pro): linux-image-5.4.0-1052-ibm 5.4.0-1052.57~18.04.1 linux-image-5.4.0-1089-raspi 5.4.0-1089.100~18.04.1 linux-image-5.4.0-1104-oracle 5.4.0-1104.113~18.04.1 linux-image-5.4.0-1105-aws 5.4.0-1105.113~18.04.1 linux-image-5.4.0-1108-gcp 5.4.0-1108.117~18.04.1 linux-image-5.4.0-1111-azure 5.4.0-1111.117~18.04.1 linux-image-5.4.0-153-generic 5.4.0-153.170~18.04.1 linux-image-5.4.0-153-generic-lpae 5.4.0-153.170~18.04.1 linux-image-5.4.0-153-lowlatency 5.4.0-153.170~18.04.1 linux-image-aws 5.4.0.1105.83 linux-image-azure 5.4.0.1111.84 linux-image-gcp 5.4.0.1108.84 linux-image-generic-hwe-18.04 5.4.0.153.170~18.04.124 linux-image-generic-lpae-hwe-18.04 5.4.0.153.170~18.04.124 linux-image-ibm 5.4.0.1052.63 linux-image-lowlatency-hwe-18.04 5.4.0.153.170~18.04.124 linux-image-oem 5.4.0.153.170~18.04.124 linux-image-oem-osp1 5.4.0.153.170~18.04.124 linux-image-oracle 5.4.0.1104.113~18.04.76 linux-image-raspi-hwe-18.04 5.4.0.1089.86 linux-image-snapdragon-hwe-18.04 5.4.0.153.170~18.04.124 linux-image-virtual-hwe-18.04 5.4.0.153.170~18.04.124 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6193-1 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2023220 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2023577 CVE-2023-35788 Package Information: https://launchpad.net/ubuntu/+source/linux/6.2.0-24.24 https://launchpad.net/ubuntu/+source/linux-aws/6.2.0-1006.6 https://launchpad.net/ubuntu/+source/linux-kvm/6.2.0-1007.7 https://launchpad.net/ubuntu/+source/linux-lowlatency/6.2.0-1007.7 https://launchpad.net/ubuntu/+source/linux-raspi/6.2.0-1007.9 https://launchpad.net/ubuntu/+source/linux/5.15.0-76.83 https://launchpad.net/ubuntu/+source/linux-aws/5.15.0-1039.44 https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1041.48 https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1037.45 https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1037.42 https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1023.28 https://launchpad.net/ubuntu/+source/linux-ibm/5.15.0-1033.36 https://launchpad.net/ubuntu/+source/linux-kvm/5.15.0-1037.42 https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-76.83 https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1028.28 https://launchpad.net/ubuntu/+source/linux-oracle/5.15.0-1038.44 https://launchpad.net/ubuntu/+source/linux-raspi/5.15.0-1033.36 https://launchpad.net/ubuntu/+source/linux/5.4.0-153.170 https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1105.113 https://launchpad.net/ubuntu/+source/linux-aws-5.15/5.15.0-1039.44~20.04.1 https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1111.117 https://launchpad.net/ubuntu/+source/linux-azure-5.15/5.15.0-1041.48~20.04.1 https://launchpad.net/ubuntu/+source/linux-azure-fde-5.15/5.15.0-1041.48~20.04.1.1 https://launchpad.net/ubuntu/+source/linux-bluefield/5.4.0-1066.72 https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1108.117 https://launchpad.net/ubuntu/+source/linux-gcp-5.15/5.15.0-1037.45~20.04.1 https://launchpad.net/ubuntu/+source/linux-gke-5.15/5.15.0-1037.42~20.04.1 https://launchpad.net/ubuntu/+source/linux-gkeop/5.4.0-1072.76 https://launchpad.net/ubuntu/+source/linux-gkeop-5.15/5.15.0-1023.28~20.04.1 https://launchpad.net/ubuntu/+source/linux-hwe-5.15/5.15.0-76.83~20.04.1 https://launchpad.net/ubuntu/+source/linux-ibm/5.4.0-1052.57 https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1094.100 https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-5.15/5.15.0-76.83~20.04.1 https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1104.113 https://launchpad.net/ubuntu/+source/linux-oracle-5.15/5.15.0-1038.44~20.04.1 https://launchpad.net/ubuntu/+source/linux-raspi/5.4.0-1089.100 . Ubuntu 22.04 and previous releases have addressed various vulnerabilities in the Linux kernel to mitigate potential denial of service attacks and prevent information exposure.. Linux Kernel Security, Ubuntu Kernel Update, Kernel Patch Process, Denial of Service Protection. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5925-1 March 06, 2023 linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-kvm: Linux kernel for cloud environments - linux-raspi2: Linux kernel for Raspberry Pi systems - linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors Details: It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461) It was discovered that a race condition existed in the Kernel Connection Multiplexor (KCM) socket implementation in the Linux kernel when releasing sockets in certain situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3521) It was discovered that the Netronome Ethernet driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3545) It was discovered that the Broadcom FullMAC USB WiFi driver in the Linux kernel did not properly perform bounds checking in some situations. A physically proximate attacker could use this to craft a malicious USB device that when inserted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3628) It was discovered that a use-after-free vulnerability existed in the Bluetooth stack in the Linux kernel. A local attacker could usethis to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3640) It was discovered that a race condition existed in the Xen network backend driver in the Linux kernel when handling dropped packets in certain circumstances. An attacker could use this to cause a denial of service (kernel deadlock). (CVE-2022-42328, CVE-2022-42329) Tamás Koczka discovered that the Bluetooth L2CAP implementation in the Linux kernel did not properly initialize memory in some situations. A physically proximate attacker could possibly use this to expose sensitive information (kernel memory). (CVE-2022-42895) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-4.15.0-1128-raspi2 4.15.0-1128.136 linux-image-4.15.0-1136-kvm 4.15.0-1136.141 linux-image-4.15.0-1146-snapdragon 4.15.0-1146.156 linux-image-kvm 4.15.0.1136.127 linux-image-raspi2 4.15.0.1128.123 linux-image-snapdragon 4.15.0.1146.145 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5925-1 CVE-2022-3521, CVE-2022-3545, CVE-2022-3628, CVE-2022-3640, CVE-2022-42328, CVE-2022-42329, CVE-2022-42895, CVE-2023-0461 Package Information: https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1136.141 https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1128.136 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1146.156 . Multiple significant vulnerabilities addressed in Linux kernel impacting Ubuntu. Prompt updates are advised to maintain system integrity.. Ubuntu Kernel Update, Security Advisory, Denial of Service, Use After Free, Linux Kernel Fix. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4945-1 May 11, 2021 linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems - linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke-5.4: Linux kernel for Google Container Engine (GKE) systems - linux-gkeop-5.4: Linux kernel for Google Container Engine (GKE) systems - linux-hwe-5.4: Linux hardware enablement (HWE) kernel - linux-oracle-5.4: Linux kernel for Oracle Cloud systems Details: It was discovered that the Nouveau GPU driver in the Linux kernel did not properly handle error conditions in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2020-25639) Jan Beulich discovered that the Xen netback backend in the Linux kernel did not properly handle certain error conditions under paravirtualization. An attacker in a guest VM could possibly use this to cause a denial ofservice (host domain crash). (CVE-2021-28038) It was discovered that the fastrpc driver in the Linux kernel did not prevent user space applications from sending kernel RPC messages. A local attacker could possibly use this to gain elevated privileges. (CVE-2021-28375) It was discovered that the Realtek RTL8188EU Wireless device driver in the Linux kernel did not properly validate ssid lengths in some situations. An attacker could use this to cause a denial of service (system crash). (CVE-2021-28660) It was discovered that the USB/IP driver in the Linux kernel contained race conditions during the update of local and shared status. An attacker could use this to cause a denial of service (system crash). (CVE-2021-29265) It was discovered that a race condition existed in the netfilter subsystem of the Linux kernel when replacing tables. A local attacker could use this to cause a denial of service (system crash). (CVE-2021-29650) Arnd Bergmann discovered that the video4linux subsystem in the Linux kernel did not properly deallocate memory in some situations. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2021-30002) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: linux-image-5.4.0-1015-gkeop 5.4.0-1015.16 linux-image-5.4.0-1039-kvm 5.4.0-1039.40 linux-image-5.4.0-1043-gcp 5.4.0-1043.46 linux-image-5.4.0-1043-gke 5.4.0-1043.45 linux-image-5.4.0-1045-oracle 5.4.0-1045.49+1 linux-image-5.4.0-1047-azure 5.4.0-1047.49 linux-image-5.4.0-1048-aws 5.4.0-1048.50 linux-image-5.4.0-73-generic 5.4.0-73.82 linux-image-5.4.0-73-generic-lpae 5.4.0-73.82 linux-image-5.4.0-73-lowlatency 5.4.0-73.82 linux-image-aws 5.4.0.1048.49 linux-image-azure 5.4.0.1047.45 linux-image-gcp 5.4.0.1043.52 linux-image-generic 5.4.0.73.76 linux-image-generic-lpae 5.4.0.73.76 linux-image-gke 5.4.0.1043.52 linux-image-gke-5.4 5.4.0.1043.52 linux-image-gkeop 5.4.0.1015.18 linux-image-gkeop-5.4 5.4.0.1015.18 linux-image-kvm 5.4.0.1039.37 linux-image-lowlatency 5.4.0.73.76 linux-image-oem 5.4.0.73.76 linux-image-oem-osp1 5.4.0.73.76 linux-image-oracle 5.4.0.1045.44 linux-image-virtual 5.4.0.73.76 Ubuntu 18.04 LTS: linux-image-5.4.0-1015-gkeop 5.4.0-1015.16~18.04.1 linux-image-5.4.0-1043-gcp 5.4.0-1043.46~18.04.1 linux-image-5.4.0-1043-gke 5.4.0-1043.45~18.04.1 linux-image-5.4.0-1044-oracle 5.4.0-1044.47~18.04.1 linux-image-5.4.0-1047-azure 5.4.0-1047.49~18.04.1 linux-image-5.4.0-1048-aws 5.4.0-1048.50~18.04.1 linux-image-5.4.0-73-generic 5.4.0-73.82~18.04.1 linux-image-5.4.0-73-generic-lpae 5.4.0-73.82~18.04.1 linux-image-5.4.0-73-lowlatency 5.4.0-73.82~18.04.1 linux-image-aws 5.4.0.1048.30 linux-image-azure 5.4.0.1047.26 linux-image-gcp 5.4.0.1043.30 linux-image-generic-hwe-18.04 5.4.0.73.82~18.04.66 linux-image-generic-lpae-hwe-18.04 5.4.0.73.82~18.04.66 linux-image-gke-5.4 5.4.0.1043.45~18.04.9 linux-image-gkeop-5.4 5.4.0.1015.16~18.04.16 linux-image-lowlatency-hwe-18.04 5.4.0.73.82~18.04.66 linux-image-oem 5.4.0.73.82~18.04.66 linux-image-oem-osp1 5.4.0.73.82~18.04.66 linux-image-oracle 5.4.0.1044.47~18.04.26 linux-image-snapdragon-hwe-18.04 5.4.0.73.82~18.04.66 linux-image-virtual-hwe-18.04 5.4.0.73.82~18.04.66 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g.linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4945-1 CVE-2020-25639, CVE-2021-28038, CVE-2021-28375, CVE-2021-28660, CVE-2021-29265, CVE-2021-29650, CVE-2021-30002 Package Information: https://launchpad.net/ubuntu/+source/linux/5.4.0-73.82 https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1048.50 https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1047.49 https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1043.46 https://launchpad.net/ubuntu/+source/linux-gke/5.4.0-1043.45 https://launchpad.net/ubuntu/+source/linux-gkeop/5.4.0-1015.16 https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1039.40 https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1045.49 https://launchpad.net/ubuntu/+source/linux-aws-5.4/5.4.0-1048.50~18.04.1 https://launchpad.net/ubuntu/+source/linux-azure-5.4/5.4.0-1047.49~18.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-5.4/5.4.0-1043.46~18.04.1 https://launchpad.net/ubuntu/+source/linux-gke-5.4/5.4.0-1043.45~18.04.1 https://launchpad.net/ubuntu/+source/linux-gkeop-5.4/5.4.0-1015.16~18.04.1 https://launchpad.net/ubuntu/+source/linux-hwe-5.4/5.4.0-73.82~18.04.1 https://launchpad.net/ubuntu/+source/linux-oracle-5.4/5.4.0-1044.47~18.04.1 . Essential kernel vulnerabilities in Ubuntu 20.04 and 18.04 LTS addressed to improve cloud defense and reliability across environments.. Kernel Issues, Ubuntu Patches, System Updates. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4748-1 February 25, 2021 linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi2, linux-snapdragon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 ESM Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-kvm: Linux kernel for cloud environments - linux-raspi2: Linux kernel for Raspberry Pi (V8) systems - linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors- linux-lts-xenial: Linux hardware enablement kernel from Xenial for Trusty Details: It was discovered that the jfs file system implementation in the Linux kernel contained an out-of-bounds read vulnerability. A local attacker could use this to possibly cause a denial of service (system crash). (CVE-2020-27815) It was discovered that the memory management subsystem in the Linux kernel did not properly handle copy-on-write operations in some situations. A local attacker could possibly use this to gain unintended write access to read-only memory pages. (CVE-2020-29374) Michael Kurth and Pawel Wieczorkiewicz discovered that the Xen event processing backend in the Linux kernel did not properly limit the number of events queued. An attacker in a guest VM could use this to cause a denial of service in the host OS. (CVE-2020-29568) Jann Horn discovered that the tty subsystem of the Linux kernel did not use consistent locking in some situations, leading to a read-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory). (CVE-2020-29660) Jann Horn discovered a race condition in the tty subsystem of the Linux kernelin the locking for the TIOCSPGRP ioctl(), leading to a use-after- free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-29661) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: linux-image-4.4.0-1088-kvm 4.4.0-1088.97 linux-image-4.4.0-1122-aws 4.4.0-1122.136 linux-image-4.4.0-1146-raspi2 4.4.0-1146.156 linux-image-4.4.0-1150-snapdragon 4.4.0-1150.160 linux-image-4.4.0-203-generic 4.4.0-203.235 linux-image-4.4.0-203-generic-lpae 4.4.0-203.235 linux-image-4.4.0-203-lowlatency 4.4.0-203.235 linux-image-4.4.0-203-powerpc-e500mc 4.4.0-203.235 linux-image-4.4.0-203-powerpc-smp 4.4.0-203.235 linux-image-4.4.0-203-powerpc64-emb 4.4.0-203.235 linux-image-4.4.0-203-powerpc64-smp 4.4.0-203.235 linux-image-aws 4.4.0.1122.127 linux-image-generic 4.4.0.203.209 linux-image-generic-lpae 4.4.0.203.209 linux-image-kvm 4.4.0.1088.86 linux-image-lowlatency 4.4.0.203.209 linux-image-powerpc-e500mc 4.4.0.203.209 linux-image-powerpc-smp 4.4.0.203.209 linux-image-powerpc64-emb 4.4.0.203.209 linux-image-powerpc64-smp 4.4.0.203.209 linux-image-raspi2 4.4.0.1146.146 linux-image-snapdragon 4.4.0.1150.142 linux-image-virtual 4.4.0.203.209 Ubuntu 14.04 ESM: linux-image-4.4.0-1086-aws 4.4.0-1086.90 linux-image-4.4.0-203-generic 4.4.0-203.235~14.04.1 linux-image-4.4.0-203-generic-lpae 4.4.0-203.235~14.04.1 linux-image-4.4.0-203-lowlatency 4.4.0-203.235~14.04.1 linux-image-4.4.0-203-powerpc-e500mc 4.4.0-203.235~14.04.1 linux-image-4.4.0-203-powerpc-smp 4.4.0-203.235~14.04.1 linux-image-4.4.0-203-powerpc64-emb 4.4.0-203.235~14.04.1 linux-image-4.4.0-203-powerpc64-smp 4.4.0-203.235~14.04.1 linux-image-aws 4.4.0.1086.83 linux-image-generic-lpae-lts-xenial 4.4.0.203.177 linux-image-generic-lts-xenial 4.4.0.203.177 linux-image-lowlatency-lts-xenial 4.4.0.203.177 linux-image-powerpc-e500mc-lts-xenial 4.4.0.203.177 linux-image-powerpc-smp-lts-xenial 4.4.0.203.177 linux-image-powerpc64-emb-lts-xenial 4.4.0.203.177 linux-image-powerpc64-smp-lts-xenial 4.4.0.203.177 linux-image-virtual-lts-xenial 4.4.0.203.177 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4748-1 CVE-2020-27815, CVE-2020-29374, CVE-2020-29568, CVE-2020-29660, CVE-2020-29661 Package Information: https://launchpad.net/ubuntu/+source/linux/4.4.0-203.235 https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1122.136 https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1088.97 https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1146.156 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1150.160 . Important vulnerabilities resolved in the Ubuntu kernel tackling various security threats that could result in service disruption or arbitrary code execution.. Ubuntu Kernel Threats,System Crash,Denial Of Service,Kernel Patch. . Severity: Critical. LinuxSecurity.com Team
The system could allow unintended access to data in some environments.. =========================================================================Ubuntu Security Notice USN-4713-1 January 28, 2021 linux-aws, linux-aws-5.4, linux-azure, linux-gcp, linux-kvm, linux-oracle, linux-raspi vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: The system could allow unintended access to data in some environments. Software Description: - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi: Linux kernel for Raspberry Pi (V8) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems Details: It was discovered that the LIO SCSI target implementation in the Linux kernel performed insufficient identifier checking in certain XCOPY requests. An attacker with access to at least one LUN in a multiple backstore environment could use this to expose sensitive information or modify data. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: linux-image-5.8.0-1013-raspi 5.8.0-1013.16 linux-image-5.8.0-1013-raspi-nolpae 5.8.0-1013.16 linux-image-5.8.0-1016-kvm 5.8.0-1016.18 linux-image-5.8.0-1018-oracle 5.8.0-1018.19 linux-image-5.8.0-1020-azure 5.8.0-1020.22 linux-image-5.8.0-1021-aws 5.8.0-1021.23 linux-image-aws 5.8.0.1021.23 linux-image-azure 5.8.0.1020.20 linux-image-kvm 5.8.0.1016.18 linux-image-oracle 5.8.0.1018.18 linux-image-raspi 5.8.0.1013.16 linux-image-raspi-nolpae 5.8.0.1013.16 Ubuntu 20.04LTS: linux-image-5.4.0-1032-kvm 5.4.0-1032.33 linux-image-5.4.0-1036-gcp 5.4.0-1036.39 linux-image-5.4.0-1037-aws 5.4.0-1037.39 linux-image-5.4.0-1037-oracle 5.4.0-1037.40 linux-image-5.4.0-1039-azure 5.4.0-1039.41 linux-image-aws 5.4.0.1037.38 linux-image-azure 5.4.0.1039.37 linux-image-gcp 5.4.0.1036.45 linux-image-kvm 5.4.0.1032.30 linux-image-oracle 5.4.0.1037.34 Ubuntu 18.04 LTS: linux-image-5.4.0-1037-aws 5.4.0-1037.39~18.04.1 linux-image-aws 5.4.0.1037.21 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4713-1 CVE-2020-28374 Package Information: https://launchpad.net/ubuntu/+source/linux-aws/5.8.0-1021.23 https://launchpad.net/ubuntu/+source/linux-azure/5.8.0-1020.22 https://launchpad.net/ubuntu/+source/linux-kvm/5.8.0-1016.18 https://launchpad.net/ubuntu/+source/linux-oracle/5.8.0-1018.19 https://launchpad.net/ubuntu/+source/linux-raspi/5.8.0-1013.16 https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1037.39 https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1039.41 https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1036.39 https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1032.33 https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1037.40 https://launchpad.net/ubuntu/+source/linux-aws-5.4/5.4.0-1037.39~18.04.1 . Enhance your Ubuntu installations immediately to rectify the kernel vulnerability outlined inSecurity Bulletin USN-4713-1, emphasizing the urgency of the update.. Linux Kernel Update, Cloud Security Advisory, Access Risk. . LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4709-1 January 28, 2021 linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 ESM Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-kvm: Linux kernel for cloud environments - linux-raspi2: Linux kernel for Raspberry Pi (V8) systems - linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors- linux-aws: Linux kernel for Amazon Web Services (AWS) systems Details: It was discovered that the LIO SCSI target implementation in the Linux kernel performed insufficient identifier checking in certain XCOPY requests. An attacker with access to at least one LUN in a multiple backstore environment could use this to expose sensitive information or modify data. (CVE-2020-28374) Wen Xu discovered that the XFS filesystem implementation in the Linux kernel did not properly track inode validations. An attacker could use this to construct a malicious XFS image that, when mounted, could cause a denial of service (system crash). (CVE-2018-13093) It was discovered that the btrfs file system implementation in the Linux kernel did not properly validate file system metadata in some situations. An attacker could use this to construct a malicious btrfs image that, when mounted, could cause a denial of service (system crash). (CVE-2019-19813, CVE-2019-19816) Bodong Zhao discovered a use-after-free in the Sun keyboard driver implementation in the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2020-25669) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: linux-image-4.4.0-1087-kvm 4.4.0-1087.96 linux-image-4.4.0-1145-raspi2 4.4.0-1145.155 linux-image-4.4.0-1149-snapdragon 4.4.0-1149.159 linux-image-kvm 4.4.0.1087.85 linux-image-raspi2 4.4.0.1145.145 linux-image-snapdragon 4.4.0.1149.141 Ubuntu 14.04 ESM: linux-image-4.4.0-1085-aws 4.4.0-1085.89 linux-image-aws 4.4.0.1085.82 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4709-1 CVE-2018-13093, CVE-2019-19813, CVE-2019-19816, CVE-2020-25669, CVE-2020-28374 Package Information: https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1087.96 https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1145.155 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1149.159 . Multiple vulnerabilities have been addressed in the Ubuntu Linux kernel across different platforms, necessitating immediate attention for updates.. Ubuntu Kernel Update, Denial of Service Fix, Linux Security Patch, Filesystem Protection. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.